django icon indicating copy to clipboard operation
django copied to clipboard

Add a note about same-origin as a referrer policy.

Open coderanger opened this issue 2 years ago • 2 comments

coderanger avatar Jun 03 '21 02:06 coderanger

Any objections to this?

coderanger avatar Sep 17 '21 21:09 coderanger

Thank goodness for MDN provides an example table to lookup the various policies and how they behave ;) Seems sensible enough to me, though I'd encourage someone with more awareness of CSRF & all the security jazz gets pinged to double-triple-check this is the right policy to recommend in such cases.

TBH I feel like the whole admonition could do with a bit of a rewording, because it's essentially "you might think you want want to do this, but don't" but phrased in an encouraging way that initially suggests you should do them...

kezabelle avatar Sep 18 '21 09:09 kezabelle

@coderanger Do you have time to keep working on this?

felixxm avatar Feb 23 '23 07:02 felixxm

Closing due to inactivity.

felixxm avatar Mar 15 '23 12:03 felixxm