Firefox 87 ichacheka zviri mukati meHTTP Referer musoro

Mozilla yakachinja nzira yainogadzira iyo HTTP Referer musoro muFirefox 87, yakarongerwa kuburitswa mangwana. Kuti uvhare zvinogona kubuda zve data yakavanzika, nekutadza kana uchienda kune dzimwe nzvimbo, Referer HTTP musoro haungasanganisi iyo yakazara URL yekwakabva kwaitwa shanduko, asi chete domain. Iyo nzira uye yekukumbira paramita ichatemwa. Avo. pachinzvimbo chekuti β€œReferer: https://www.example.com/path/?arguments”, β€œReferer: https://www.example.com/” ichatumirwa. Kutanga neFirefox 59, kuchenesa uku kwakaitwa mune yakavanzika yekubhurawuza modhi, uye zvino ichawedzerwa kune main mode.

Hunhu hutsva huchabatsira kudzivirira kuendeswa kweasina basa mushandisi data kune advertising network uye zvimwe zviwanikwa zvekunze. Semuenzaniso, dzimwe nzvimbo dzekurapa dzinopihwa, mukuita kwekuratidzira kushambadza uko mapato echitatu anogona kuwana ruzivo rwakavanzika, sezera remurwere uye kuongororwa. Panguva imwecheteyo, kubvisa ruzivo kubva kuReferer kunogona kukanganisa kuunganidzwa kwenhamba pamusoro peshanduko nevaridzi vesaiti, avo vasingazokwanise kunyatso tsanangura kero yepeji yapfuura, semuenzaniso, kunzwisisa kuti ndechipi chinyorwa chakaitwa. kubva. Zvinogonawo kukanganisa kushanda kwemamwe masimba ekugadzirwa kwemukati masisitimu anokwenenzvera makiyi akatungamira kune shanduko kubva kune yekutsvaga injini.

Kudzora marongero eReferer, iyo Referrer-Policy HTTP musoro unopihwa, iyo varidzi vesaiti vanogona kudarika maitiro ekusarudzika ekuchinja kubva panzvimbo yavo uye kudzosera ruzivo ruzere kune Referer. Parizvino, iyo default policy ndeye "no-referrer-when-downgrade", uko Referer isingatumirwe kana ichidzika kubva paHTTPS kuenda kuHTTP, asi inotumirwa yakazara fomu pakurodha zviwanikwa paHTTPS. Kutanga neFirefox 87, iyo "strict-origin-when-cross-origin" mutemo unotanga kushanda, zvinoreva kucheka nzira neparamende paunenge uchitumira chikumbiro kune mamwe mauto kana uchinge wasvika kuburikidza neHTTPS, uchibvisa Referer kana uchichinja kubva kuHTTPS kuenda. HTTP, uye kupfuudza iyo yakazara Referer yemukati shanduko mukati meimwe saiti.

Shanduko iyi ichashanda kune zvakajairika zvikumbiro zvekufamba (zvinotevera zvinongedzo), otomatiki redirects, uye kana uchirodha zviwanikwa zvekunze (mifananidzo, CSS, zvinyorwa). MuChrome, shanduko yekuenda ku "strict-origin-when-cross-origin" yakaitwa zhizha rapfuura.

Source: opennet.ru

Voeg