Re: confidentiality and the referer field

> Assuming you're not suggesting removing the REFERER header field
> altogether, that's not true.  Sites would simply need to decide whether
> a request without a REFERER was acceptable or not, and allow or deny
> the request accordingly.

OK "restrict the ability".

There are already many situations where a browser can't send a referer
field, such as when the link is a bookmark. As clients allow the user to
disable the referer field sites will be less able to refuse requests
for frivolous reasons.

I was simply flagging a secondary consequence of the change.


	Phill

Received on Thursday, 26 June 1997 13:31:03 UTC