Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • Home
  • SEARCH
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 3307800
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 17, 20262026-05-17T21:26:53+00:00 2026-05-17T21:26:53+00:00

Section 15.1.3 in RFC 2616 states: Clients SHOULD NOT include a Referer header field

  • 0

Section 15.1.3 in RFC 2616 states:

Clients SHOULD NOT include a Referer header field in a (non-secure) HTTP request if the referring page was transferred with a secure protocol

However, I know many browsers have bugs and don’t always follow spec, plus it only says SHOULD NOT, instead of MUST NOT. So my question is therefore:

1) Is there any browser (past, present, or beta) that breaks spec and DOES send the referer header when a request is made from a secure site
2) Are there any tools, browser plugins, or any way at all to modify a browser to break spec and send the referer header when making such a request
3) Is there any official sounding source, or load of information from security pros about this problem anywhere on the web that I can look at.

For a bit of background, this is part of a security review of my app which runs over SSL, and the spec is that no referer information should be sent to 3rd party sites. My testing has found no browser that will send the referer header in this scenario, but I would like to be very confident that I’m right.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-17T21:26:54+00:00Added an answer on May 17, 2026 at 9:26 pm

    By default in Firefox, if the 3rd-party site is over HTTPS, the referer header will be sent, according to the network.http.sendSecureXSiteReferrer option (accessible via about:config in the address bar).

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

The section Last links in the chain: Stashing and the reflog in http://ftp.newartisans.com/pub/git.from.bottom.up.pdf recommends
My question is about how to reply a HTTP 304 Not Modified when I
If no charset parameter is specified in the Content-Type header, RFC2616 section 3.7.1 seems
Im implementing NFS and almoste done but the RFC section 3.3.8 says this in
SAPs Transactional RFC Technical Description document (release 4.0, see http://www.sdn.sap.com/irj/scn/go/portal/prtroot/docs/library/uuid/ee6bca90-0201-0010-5792-d9693e2eac83?QuickLink=index&overridelayout=true ) says in section
.section .data astring: .asciz 11010101 format: .asciz %d\n .section .text .globl _start _start: xorl
I refactored a slow section of an application we inherited from another company to
The Project's Web section (under project properties in VS2008) has a list of debuggers:
I have a section of makefile that has this sort of structure: bob: ifdef
If I have several Section elements in an XML document, what XQuery do I

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.