Are there any browsers that set the origin header to “null” for privacy-sensitive contexts?

后端 未结 4 750
故里飘歌
故里飘歌 2020-12-01 01:21

The Origin spec indicates that the Origin header may be set to \"null\". This is typically done when the request is coming from a file on a user\'s computer rat

4条回答
  •  盖世英雄少女心
    2020-12-01 02:19

    There are a few other cases related to iframe which can cause a null origin: https://webdbg.com/test/sandbox/frames.htm

提交回复
热议问题