Just because it's supposed to work that way
Doesn't necessarily mean that it isn't a security flaw. Just that the flaw started in the design phase.
A security researcher warns that Google Gmail is vulnerable to an Open URL redirection flaw, a finding disputed by Google itself. The alleged bug creates a means for attackers to send intended victims a special crafted UR before stealing credentials or tricking them into visiting a malicious website, according to security …