Firefox 87 will limit the content of the HTTP Referer header

Mozilla has changed the way the HTTP Referer header is formed in the upcoming release of Firefox 87, scheduled for tomorrow. To block potential leaks of confidential data by default when navigating to other sites, the HTTP Referer header will include not the full URL of the source from which the navigation occurred, but only the domain. The path and query parameters will be cut off. For example, instead of "Referer: https://www.example.com/path/?arguments", it will send "Referer: https://www.example.com/". Starting with Firefox 59, similar cleanup was done in private browsing mode, and now it will be extended to the main mode.

The new behavior will help prevent unnecessary user data from being shared with advertising networks and other external resources. For instance, some medical websites are mentioned, where third parties may obtain confidential information such as age and the diagnosis given to the patient during ad display. However, the removal of details from the Referer may negatively impact the collection of traffic statistics by website owners, who will now be unable to accurately determine the address of the previous page, such as understanding from which specific article the navigation occurred. The functioning of some dynamic content generation systems that parse keys leading to navigation from the search engine may also be disrupted.

To manage the Referer exhibition, the HTTP header Referrer-Policy is provided, allowing site owners to override the default behavior for navigation from their site and restore the inclusion of the full information in the Referer. The default policy currently applied is "no-referrer-when-downgrade", whereby the Referer is not sent when navigating from HTTPS to HTTP, but is sent in full form when loading resources over HTTPS. Starting with Firefox 87, the policy "strict-origin-when-cross-origin" will take effect, implying the removal of paths and parameters when sending requests to other hosts when accessing via HTTPS, removal of the Referer when navigating from HTTPS to HTTP, and transmission of the full Referer for internal navigations within the same site.

The change will apply to regular navigation requests (following links), automatic redirects, and when loading external resources (images, CSS, scripts). In Chrome, the default switch to 'strict-origin-when-cross-origin' was implemented last summer.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster