SECURITY: Onebox canonical links bypassing FinalDestination checks (PR #13605)

GitHub