I am attempting a Manual Explore of an application but am running into a problem with a 308 Redirect loop. I put my base website url into Manual Explore (ex. "
https://example.io"), then see the same URL in the history but with an added "/" at the end (ex. "
https://example.io/"). The response from this initial GET is a 308 redirect back to the url without the "/" (ex. "
https://example.io"), but the next entry in the ZAP history pane has the trailing "/" back again so it ends up looping.
Has anyone ever seen this type of behavior before? I am not able to get the 308 redirect any other way. The automated scan seems to work fine and if I curl the url directly with the "/" I just get the expected page, not the redirect. This also works if I put either URL directly into the browser (without the ZAP proxy). I am stumped. Any help would be appreciated.
Thanks,
Jon