URL Redirect Parameters Are No Longer Case-Sensitive

The protected URL parameters used in Visualforce pages—retURL, startURL, cancelURL, and saveURL—are no longer case-sensitive. If you change the parameter value from retURL to returl, the system now recognizes it as a protected parameter. Protected URL parameters allow redirects from Visualforce pages to salesforce.com or *.force.com domains and prevent malicious redirects to third-party domains.

Where: This change applies to Lightning Experience, Salesforce Classic, and all versions of the Salesforce app in Professional, Performance, and Unlimited editions.