mathdown icon indicating copy to clipboard operation
mathdown copied to clipboard

Security: hide secret doc id from Referer header

Open cben opened this issue 11 years ago • 1 comments

Almost not an issue now but blocker for #9: Since the URL is secret, directly linking to external sites would expose the URL in Referer: header.

Should probably use an extra redirect. Is there a way to keep the link structure search-engine friendly? Links on public pages should count as links. OTOH, if they're publicly editable they probably shouldn't to deter spam?

Alternitive: I'm again tempted to keep secret portion in #fragment, which should not (though sometimes did) leak via Referer.

cben avatar Sep 14 '13 01:09 cben

Confirmed: clicking ⚠ Alpha quality! ⚠ (link to GH issues) sends Referer: http://mathdown.net/?doc=about to Github.

cben avatar Dec 31 '14 21:12 cben