3 ms·
You left out the part which contradicts your claim. > Don't send the Referer header to less secure destinations (HTTPS→HTTP). The referer header is still sent
by vince14 5y ago
You left out the part which contradicts your claim.
> Don't send the Referer header to less secure destinations (HTTPS→HTTP).
The referer header is still sent from HTTPS to HTTPS.
- londons_explore 5y agoYes, but only with the domain not the full path. Does anyone really care that the domain is leaked? There are very few secret domains...