Last modified: 2012-10-22 02:32:42 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T43265, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 41265 - HTTP referer is sent from secure connection
HTTP referer is sent from secure connection
Status: RESOLVED INVALID
Product: MediaWiki
Classification: Unclassified
General/Unknown (Other open bugs)
unspecified
All All
: Unprioritized normal (vote)
: ---
Assigned To: Nobody - You can work on this!
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2012-10-22 02:25 UTC by Smallman
Modified: 2012-10-22 02:32 UTC (History)
0 users

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Smallman 2012-10-22 02:25:25 UTC
When on a secure wiki page (SSL), such as 
http://en.wikipedia.org/wiki/File:Vulpicida_canadensis_44260.jpg

and you click a non-secure (http not https) link, such as
http://www.mushroomobserver.org/image/show_image/44260

the referer is sent. This is against RFC 2616. No referer should be sent.

Per RFC 2616 ยง 15.1.3 (http://tools.ietf.org/html/rfc2616#section-15.1.3):

   Clients SHOULD NOT include a Referer header field in a (non-secure)
   HTTP request if the referring page was transferred with a secure
   protocol.

General http referer info: http://en.wikipedia.org/wiki/HTTP_referer
Comment 1 Smallman 2012-10-22 02:32:42 UTC
Seems it doesn't send...my mistake.

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links