3 ms·
Surely there is no refer on a cross-domain navigation from an HTTPS site [1], and so the magic string won't make it there either. [1] If there was, this could
by Robin_Message 14y ago
Surely there is no refer on a cross-domain navigation from an HTTPS site [1], and so the magic string won't make it there either.
[1] If there was, this could leak, for example, session ID in URL, which would be very bad on a supposedly secure site.
- tonfa 14y agoGoogle does a redirect to http before sending you out because of that... just look in the dev tools from your browser.
- Robin_Message 14y agoAh, I understand what you mean now - Google deliberately redirect to their own site on http in order to "leak" that information in the referrer header. So we're both right, I just didn't understand you, sorry.