Skip to content

Conversation

vin01
Copy link
Contributor

@vin01 vin01 commented Jan 6, 2018

It will set a default strict Referrer-Policy strict-origin-when-cross-origin that controls what referrer information shall be included with requests.
More: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy, https://scotthelme.co.uk/a-new-security-header-referrer-policy/
It can prevent issues like: https://robots.thoughtbot.com/is-your-site-leaking-password-reset-links

It will set a default strict `Referrer-Policy ``strict-origin-when-cross-origin`` that controls what referrer information shall be included with requests.
More: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy, https://scotthelme.co.uk/a-new-security-header-referrer-policy/
It can prevent issues like: https://robots.thoughtbot.com/is-your-site-leaking-password-reset-links
@notzippy notzippy added this to the v0.19 milestone Jan 16, 2018
@notzippy notzippy changed the base branch from master to develop January 30, 2018 05:26
@notzippy notzippy merged commit 4c87861 into revel:develop Jan 30, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants