Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove referer header by default. #1

Open
sctthrvy opened this issue Dec 1, 2015 · 1 comment
Open

Remove referer header by default. #1

sctthrvy opened this issue Dec 1, 2015 · 1 comment

Comments

@sctthrvy
Copy link
Collaborator

sctthrvy commented Dec 1, 2015

This seems like the area to remove the most false positives. For example, pretty much all requests are blocked when I go to github.com/scotte/nicstat. This url contains my name so requests coming from the page have "scott" in the referer. We detect this as a leak of PII, thus blocking the innocent requests.

I feel like there are two good options:

  1. Remove all referers, then let the request through.
    • Would be a options checkbox.
  2. Remove referers which contain PII, then let the request through.
    • Would be displayed clearly in the popup.

I'm leaning towards 2.

@mjsalerno
Copy link
Owner

I think I agree with 2 as well.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants