Can you at least get the domain of the https referer?

前端 未结 2 1523
被撕碎了的回忆
被撕碎了的回忆 2021-01-27 07:50

I\'ve noticed that if a foreign https: site links to my non-https site, that I don\'t get anything in the HTTP Referer header at all. I\'ve experienced this with <

2条回答
  •  死守一世寂寞
    2021-01-27 08:28

    You should check this answer : Get referrer URL - visitors coming from Paypal (HTTPS)


    In case your site uses HTTP (not HTTPS) and the referer uses HTTPS, there is no Referrer being sent!

    HTTP RFC - 15.1.3 Encoding Sensitive Information in URI's states:

    Clients SHOULD NOT include a Referer header field in a (non-secure) HTTP request if the referring page was transferred with a secure protocol.

    So the only way to get the Referrer is to use HTTPS on your site.

提交回复
热议问题