Whether the scope is checked on every hop of a redirect chain instead of only on the
URL requested by the frontend. Defaults to false.
When disabled, a server on an allowed origin can answer with a redirect to any other
origin - an open redirect, or a server an attacker controls - and the plugin follows it,
handing the webview a response from a URL the scope denies, such as a localhost
service, an internal host or a cloud metadata endpoint.
When enabled, a redirect to a URL that is not allowed by the scope fails with
Error::UrlNotAllowed instead of being followed, so every
redirect target must also be part of the scope. This is opt-in because it breaks
applications that rely on being redirected outside of their configured scope.