in app/config/LoginConfig.scala [69:78]
def isValidUrl(domain: String, returnUrl: String): Boolean = {
try {
val uri = URI.create(returnUrl)
// valid url, matches panda domain and is secure
uri.getHost.endsWith(domain) && uri.getScheme == "https"
} catch {
// invalid url
case NonFatal(_) => false
}
}