The
Referer
header is strictly optional according to w3.org standards.
Hence although most browsers implement it, using it to control application
functionality should be regarded as a “hack.”
It is often assumed that HTTP headers are somehow
more “tamper-proof” than other parts of the request, such as the URL. This
may lead developers to implement functionality that trusts the values
submitted in headers such as
Cookie
and
Referer
, while performing proper
validation of other data such as URL parameters. This perception is false —
Do'stlaringiz bilan baham: