Skip to content
This repository has been archived by the owner on Jan 24, 2019. It is now read-only.

Don't pass Referer header to protected server on call-back. #134

Open
nightlyone opened this issue Aug 17, 2015 · 0 comments
Open

Don't pass Referer header to protected server on call-back. #134

nightlyone opened this issue Aug 17, 2015 · 0 comments

Comments

@nightlyone
Copy link

Because it contains sensitive info from the callback.
e.g. Referer: https://accounts.google.com/o/oauth2/auth?access_type=offline ......

No big problem, but unnecessary.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Development

No branches or pull requests

1 participant