-
Notifications
You must be signed in to change notification settings - Fork 391
Limit the length of the Referer header #903
Copy link
Copy link
Closed
w3c/webappsec-referrer-policy
#122Labels
impacts documentationUsed by documentation communities, such as MDN, to track changes that impact documentationUsed by documentation communities, such as MDN, to track changes that impact documentationsecurity/privacyThere are security or privacy implicationsThere are security or privacy implicationstopic: http
Metadata
Metadata
Assignees
Labels
impacts documentationUsed by documentation communities, such as MDN, to track changes that impact documentationUsed by documentation communities, such as MDN, to track changes that impact documentationsecurity/privacyThere are security or privacy implicationsThere are security or privacy implicationstopic: http
As it's attacker-controlled it can be used for cache-eviction or determining cookie size.
To quote @mikewest in https://bugs.chromium.org/p/chromium/issues/detail?id=959757 (it's worth reading this for some more relevant discussion):
cc @whatwg/security