Closed Bug 861237 Opened 13 years ago Closed 13 years ago

Cannot save changes on MDN because MDN requires user-agent to send the referer header in order to edit pages

Categories

(developer.mozilla.org Graveyard :: General, defect)

All
Other
defect
Not set
normal

Tracking

(Not tracked)

RESOLVED DUPLICATE of bug 789016

People

(Reporter: briansmith, Unassigned)

Details

(Whiteboard: [specification][type:bug])

What did you do? ================ a What happened? ============== b What should have happened? ========================== c Is there anything else we should know? ====================================== (In reply to Kohei Yoshino from bug 834836 comment #53) > Thanks for your correcting. Tanvi: you have to enable HTTP referer on MDN to > save your changes. I have an add-on installed to send referer only when I > save. MDN issues a Cookie called "csrftoken" but it also refers HTTP referer > to avoid CSRF attacks. Very annoying security practice, IMO. We shouldn't require the referer header to be sent when editing pages on MDN. We preferences for disabling the referer header in Firefox, and we have many extensions on AMO for preventing the referer header from being sent. And, some privacy people that work on Firfox/Gecko would like us to send less (or no) referer header in the future. So, the full functionality of MDN should work correctly even when the referer header is not sent.
Status: NEW → RESOLVED
Closed: 13 years ago
Resolution: --- → DUPLICATE
Product: developer.mozilla.org → developer.mozilla.org Graveyard
You need to log in before you can comment on or make changes to this bug.