fix security test for redirect. Also set common server variables to mimick a real...