-
Suggestion
-
Resolution: Won't Fix
-
None
Currently when external links are entered into Confluence pages, the link points directly to the linked page. This allows the linked site to harvest internal addresses (potentially containing page titles) of a private Confluence instance by logging the browser referrer header.
Confluence should have an option to enable "safe external links". This should include two features: allow the administrator to specify a list of "safe sites" (such as all internal servers) where linking can be direct. Then, if safe linking is enabled, Confluence would link to any pages which aren't on the safe list through an redirect page which would clear the browser referrer.
From: https://confluence.atlassian.com/confkb/how-do-i-hide-referrer-info-to-linked-external-sites-779293508.html/:
Confluence users may wish to anonymise external links that exists in their Confluence pages to make sure that the external Websites owners will not be able to see that their sites are being linked in their Confluence page.
- is superseded by
-
CONFCLOUD-67239 Add feature to hide referrer info to linked external sites
- Gathering Interest
- relates to
-
CONFSERVER-4085 Safe external links
- Closed