mirror of
https://github.com/cypht-org/cypht.git
synced 2026-04-25 13:05:53 +03:00
[PR #373] [MERGED] [Privacy] Don't send referrer information when clicking links #795
Labels
No labels
2fa
I18N
PGP
Security
Security
account
advanced_search
advanced_search
announcement
api_login
authentication
awaiting feedback
blocker
bug
bug
bug
calendar
config
contacts
core
core
devops
docker
docs
duplicate
dynamic_login
enhancement
epic
feature
feeds
framework
github
github
gmail_contacts
good first issue
help wanted
history
history
imap
imap_folders
inline_message
installation
keyboard_shortcuts
keyboard_shortcuts
ldap_contacts
mobile
need-ssh-access
new module set
nux
pop3
profiles
pull-request
question
refactor
release
research
saved_searches
smtp
strategic
tags
tests
themes
website
wordpress
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/cypht#795
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
📋 Pull Request Information
Original PR: https://github.com/cypht-org/cypht/pull/373
Author: @t-m-w
Created: 2/11/2020
Status: ✅ Merged
Merged: 2/16/2020
Merged by: @jasonmunro
Base:
master← Head:master📝 Commits (1)
adc5c54[Privacy] Don't send referrer information when clicking links📊 Changes
2 files changed (+2 additions, -1 deletions)
View changed files
📝
modules/core/output_modules.php(+1 -0)📝
tests/phpunit/modules/core/modules.php(+1 -1)📄 Description
Pullrequest
This PR adds a meta tag to pages that prevents referrer information from being transmitted in HTTP request headers when you click links, such as links in emails. Sending that information to external sites unnecessarily exposes the full URL of the cypht page you were on, which includes your cypht instance domain/address, message ID, and other IDs which might be usable for unknown nefarious purposes. The URL often looks something like this:
https://cypht.example.com/?page=message&uid=12345&list_path=imap_0_1234567890&list_parent=imap_0_1234567890&list_page=1🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.