RE: Referer URI MUST NOT include a fragment

I think the idea of allowing fragment identifiers in
Referer is interesting, and I'm not sure what it would
break. It couldn't be mandated. I think the privacy
security concerns about Referer remain, and perhaps
the restriction was just a way of minimizing the

The important limits on Referer in RFC 2616
are in the "Security Considerations" section

At least a while ago, it was looking like the
"Origin" header proposal might instead be subsumed
by an extension to "Referer" instead, which seemed
like a positive direction. I don't think allowing
fragment identifiers in Referer for other purposes
would interfere with that.


Received on Thursday, 26 February 2009 00:08:04 UTC