preserving headers on redirects includes a potential security risk because on redirect to a different domain credential headers would be leaked.