Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Opt-in setting recording / remove referer #55

Closed
trochr opened this issue Oct 30, 2014 · 1 comment
Closed

Opt-in setting recording / remove referer #55

trochr opened this issue Oct 30, 2014 · 1 comment
Labels

Comments

@trochr
Copy link
Owner

trochr commented Oct 30, 2014

The read speed setting being stored/recovered from an external call to the API hosted on Heroku, this has for consequence that the URL of the web page being scrolled is accessible from the API by the referer header, which might causes privacy concerns.
What can be done ?

  • have some kind of referer removal in the bookmarklet code
  • make it "opt-in" to save the setting (usability issue)
@trochr
Copy link
Owner Author

trochr commented Sep 13, 2016

The simple click on the bookmark leaks that. No easy fix for that. CORS is there for that, should a website wish to protects its visitors against that.

@trochr trochr closed this as completed Sep 13, 2016
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant