3 ms·
If it's a page that contain or receive secret should be using https where referrer is already stripped off
by fvv 6y ago
If it's a page that contain or receive secret should be using https where referrer is already stripped off
- jefftk 6y agoFirefox was using no-referrer-when-downgrade, which only strips refers when navigating from HTTPS to HTTP. They are switching to strict-origin-when-cross-origin, which cuts the referrer down to just the origin when navigating to a different origin.