Re: WebAppSec re-charter status

On Thu, Feb 12, 2015 at 9:32 PM, Eduardo' Vela" <Nava> <evn@google.com> wrote:
> The status quo is that someone that wanted to make deep linking impossible
> on their site, would need to 403 all requests without the right referrer.

The last time Google studied that header I think it turned out for 5%
of users things would break if something like that were to happen.
It's why we have a distinct Origin header. Now if we limit things to
TLS, maybe?


-- 
https://annevankesteren.nl/

Received on Thursday, 12 February 2015 20:36:20 UTC