Cookie and Authorization headers are leaked when following cross-origin redirects in twited.web.client.RedirectAgent and twisted.web.client.BrowserLikeRedirectAgent.
twited.web.client.RedirectAgent
twisted.web.client.BrowserLikeRedirectAgent