6 ms·
I've seen that (current) browsers won't send Origin / Referer Header for GET and HEAD requests, so I'm whitelisting these request types. Other than that, it se
by red0point 8y ago
I've seen that (current) browsers won't send Origin / Referer Header for GET and HEAD requests, so I'm whitelisting these request types.
Other than that, it seems that IE is not sending the Origin Header for POST requests, so I simply use the Referer Header in this scenario.
Assume an attacker site sets the Referrer Policy header to no-referrer, IE sends no Referer / Origin at all for POST requests, so I block those requests.
The real origin must thus not have a Referrer Policy of "no-referrer".
Other than that, I'm observing the impact of the rule in production but haven't encountered any problems thus far.