Skip to content
Back to skills

Referrer Policy

ASecurity

Use when reviewing HTTP response headers for privacy hardening on any website that handles authentication, session state, or sensitive URL parameters.

  • 74,358 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 5, 2026
developmentgofrontendsecurity

Works with

  • cli

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned October 5, 2026

npx -y skills add thedaviddias/Front-End-Checklist --skill referrer-policy --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Referrer Policy?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Referrer Policy
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/thedaviddias-referrer-policy/badge)](https://www.skillsdirectory.com/skills/thedaviddias-referrer-policy)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: referrer-policy
description: "Use when reviewing HTTP response headers for privacy hardening on any website that handles authentication, session state, or sensitive URL parameters."
metadata:
  category: security
  priority: medium
  difficulty: beginner
  estimatedTime: "10"
  source: frontendchecklist.io
  url: https://frontendchecklist.io/rules/security/referrer-policy
---

# Set a Referrer-Policy header

Without a Referrer-Policy, a password reset link like `https://example.com/reset?token=abc123` is included in the `Referer` header when the user clicks an external link on that page — leaking the token to third parties.

## Quick Reference

- Use `Referrer-Policy: strict-origin-when-cross-origin` — the recommended modern default
- `strict-origin-when-cross-origin` sends the full URL for same-origin requests, only the origin for cross-origin HTTPS, and nothing for HTTPS→HTTP
- Never use `unsafe-url` — it sends the full URL including path and query string to every external site
- Can be set via HTTP header, `<meta>` tag, or the `referrerpolicy` attribute on individual `<a>` and `<img>` elements
- Sensitive URLs (reset tokens, private IDs) in query strings can be exposed via the Referer header if policy is too permissive

## Check

Check whether the server sends a Referrer-Policy header and verify the value is appropriate. The recommended value is strict-origin-when-cross-origin. Check for any pages with sensitive URL parameters that could be leaked via the Referer header.

## Fix

Add Referrer-Policy: strict-origin-when-cross-origin to all HTTP responses. Configure it in your web server, CDN, or application framework. For pages with particularly sensitive URLs, consider no-referrer or same-origin.

## Explain

Explain what the Referer header contains, how a permissive Referrer-Policy can leak sensitive URL parameters to third parties, and what the difference is between the various Referrer-Policy values.

## Code Review

Review server config, headers, forms, and integration points related to Set a Referrer-Policy header. Flag exact responses, cookies, or browser behaviors that violate the rule, and verify them against the effective production-like response.

---

For full implementation details, code examples, and framework-specific guidance,
see `references/rule.md`.

Rule page: https://frontendchecklist.io/rules/security/referrer-policy

Files in this skill

  • SKILL.md2.3 KB
  • references/rule.md4.5 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…