From 49bca5e3a87b7f675c6e28407cee8afdae4d2247 Mon Sep 17 00:00:00 2001 From: claustromaniac <20734810+claustromaniac@users.noreply.github.com> Date: Tue, 25 Dec 2018 16:20:48 -0300 Subject: [PATCH] fix referer spoofing Match the behavior of network.http.referer.spoofSource (send full URI), to avoid raising entropy unnecessarily. --- src/bg/webRequest.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/bg/webRequest.js b/src/bg/webRequest.js index 790c1f4..c690b86 100644 --- a/src/bg/webRequest.js +++ b/src/bg/webRequest.js @@ -95,7 +95,7 @@ if (origin) { if (referer) { if (settings.referers) { - newHeaders.push({name:'Referer', value:`${target.origin}/`}); + newHeaders.push({name:'Referer', value:`${d.url}`}); console.debug( `Privacy-Oriented Origin Policy: Referer spoofed (request #${d.requestId})\n${target.origin}` );