{"repo":"garywill/autoReferer","free":true,"listed":false,"github":"https://github.com/garywill/autoReferer","clone":"git clone https://github.com/garywill/autoReferer.git","description":"Browser addon. Control referer to protect privacy and not break web. The addon (maybe the only one?) that deals with Firefox's document.referrer bug 🛡️🛣️","language":"JavaScript","stars":32,"topics":["firefox","firefox-addon","referer","privacy","extension","referrer-policy","referer-spoof","referrer","browser","webextension"],"license":"GPL-2.0","category":"self-hosted-apps","readme_excerpt":"Auto Referer Control HTTP referer to protect privacy and not break web. - Firefox Addon - Chrome Addon (Manifest v2 needed) Notice : Due to browser bug on javascript document.referrer on Firefox 69+ (1601496, 1601743) (also on Chrome ), using a regular referer controlling addon you can get 70% of expected protection until they fix that bug. So, we've implemented a workaround to improve protection to 85%. Please enable workaround in addon settings . Referer Policy of this Addon 1. For webs' top frame (i.e. clicking link, navigating, redirecting etc.): 1. If origin and target url have same domain, allow trimmed referer 2. If origin and target url have different domain, no referer 2. For in-page resources (images, videos, js, css etc.), allow trimmed referer (this is the key to not break most webs, also a balance between privacy and experience) 3. Trim referer: Any referer should be no more than http(s)://domain-name:port/ (like Firefox's native about:config setting network.http.referer.trimmingPolicy = 2 ). 4. Not allow referer that not starts with \"http\" or \"https\". (Please feedback if you find something broken due to this) 5. No referer when downgrade from HTTPS/WSS to HTTP/WS We believe that can protect privacy enough and won't break web. document.referrer bug workaround This addon doesn't use content script. Content script hiding document.referrer is not 100% reliable. Instead, we use this workaround to kill document.referrer : Cancel all cross-domain navigating requests an","default_branch":null,"files":null,"tree":[],"storefront":"/r/garywill","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/garywill/autoReferer/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}