Why isn't the the Referer header removed for Google HTTPS -> HTTP?

后端 未结 3 678
野的像风
野的像风 2021-01-03 08:00

Clients SHOULD NOT include a Referer header field in a (non-secure) HTTP request if the referring page was transferred with a secure protocol.” htt

3条回答
  •  我在风中等你
    2021-01-03 08:41

    I think its because Google uses

    
    

    So when a person goes from HTTPS to a HTTP site, the referrer is kept. Otherwise, without this the referrer would be stripped.

提交回复
热议问题