At my organization, we have implemented a suggestion for fixing Cross-Site History Manipulation by appending a random GUID to the end of the URL on a redirect.
For example:
Response.Redirect($"{path}¶mX={Guid.NewGuid():N}");
So if the user has visited the page https://www.example.com/default.aspx then the redirect behavior would be the following:
Response.Redirect("https://www.example.com/default.aspx?¶mX=d11712a771294de8a6fc0c66e92954fc");
The issue or question comes into play if the Redirect happens when the user has already been redirected once or multiple times. In that case, duplicate params will be appended each time such as the following:
Response.Redirect("https://www.example.com/default.aspx?¶mX=d11712a771294de8a6fc0c66e92954fc¶mX=ff4bc6a838684b198060c70091b300e2");
Is there a limit on the URL length this could run into if excessive redirects happen?
If so, my solution to this would be to use a RegEx to detect if the param exists each time and use RegEx Replace( ) to replace it rather than appending each time.