Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Feature] 建议Referrer Policy / Referer可自定义 #64

Closed
hy597 opened this issue Jan 15, 2024 · 1 comment
Closed

[Feature] 建议Referrer Policy / Referer可自定义 #64

hy597 opened this issue Jan 15, 2024 · 1 comment
Assignees
Labels
enhancement New feature or request

Comments

@hy597
Copy link

hy597 commented Jan 15, 2024

作者你好,感谢开源sun-panel

目前使用v1.2.1版本过程中发现有部分网页/私有化部署的服务会检测Referer,类似Referer防盗链一样的功能。
请问能否在配置添加项目设置跳转地址的时候增加一些功能?例如:

  • 设置不携带Referer或携带为空
  • 携带指定Referer
  • 或者服务端提供高级参数可以自定义Referrer Policy将策略放宽松一些

跳转到无法打开的网页F12部分信息

Referrer Policy: strict-origin-when-cross-origin
Pragma: no-cache
Referer: http://10.0.0.24/

无法打开的网页后台tomcat信息

2024-01-15 15:14:53 [Error] [src\httpd\HttpServletRequest.cpp] [196] [HedExHS] {16800} The Referer http://10.0.0.24/ is not the same as the Host http://x.x.x.x:7890 in the request header.
@hy597 hy597 added the enhancement New feature or request label Jan 15, 2024
@hslr-s hslr-s self-assigned this Apr 19, 2024
@hslr-s
Copy link
Owner

hslr-s commented Apr 22, 2024

你好,我目前正在开发这一部分

目前我尝试增加了<meta name="referrer" content="never">,但是在火狐浏览器未生效,edge可以,在chrome中如果是从导航站跳转,每次都需要输入账号密码才可进入,我用的测试网站是自搭建的qBittorrent。(目前暂定这个方案,也会在未来应用到v1.4.0的正式版本上)

现在想请问,你对Referer这部分知识是否了解,如果了解并知道解决方案欢迎对此贴进行回复告知,谢谢。

@hslr-s hslr-s closed this as completed Apr 26, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants