Ability to disable/configure the Referrer-Policy flag in security headers

XMLWordPrintable

    • Type: Suggestion
    • Resolution: Unresolved
    • None
    • Component/s: Tomcat
    • None
    • 1
    • 9

      Customer would like to change the Referrer-Policy header to "strict-origin", so It doesn't make data leakage and never share the full URL, even for same-origin requests. However Referrer-Policy: strict-origin-when-cross-origin header is hardcoded in our sources, so there is no way to disable or configure it at application level.

       

            Assignee:
            Unassigned
            Reporter:
            Neel
            Votes:
            7 Vote for this issue
            Watchers:
            5 Start watching this issue

              Created:
              Updated: