4 ms·
The destination site still receives the referrer header, sent by your browser via HTTPS. Further measures are needed like this one.
by vince14 5y ago
The destination site still receives the referrer header, sent by your browser via HTTPS.
Further measures are needed like this one.
- londons_explore 5y agoYou're mistaken. MdN says: strict-origin-when-cross-origin (default) Send the origin, path, and querystring when performing a same-origin request. For cross-origin requests send the origin (only) when the protocol security level stays same (HTTPS→HTTPS). So no path is sent to the destination of a link over https - only the domain.
- vince14 5y agoYou left out the part which contradicts your claim. > Don't send the Referer header to less secure destinations (HTTPS→HTTP). The referer header is still sent from HTTPS to HTTPS.
- londons_explore 5y agoYes, but only with the domain not the full path. Does anyone really care that the domain is leaked? There are very few secret domains...