Set Referrer-Policy to no-referrer for media (#7009)
							parent
							
								
									477c4f5b1c
								
							
						
					
					
						commit
						96071eea8f
					
				| 
						 | 
					@ -0,0 +1 @@
 | 
				
			||||||
 | 
					Set `Referrer-Policy` header to `no-referrer` on media downloads.
 | 
				
			||||||
| 
						 | 
					@ -50,6 +50,9 @@ class DownloadResource(DirectServeResource):
 | 
				
			||||||
            b" media-src 'self';"
 | 
					            b" media-src 'self';"
 | 
				
			||||||
            b" object-src 'self';",
 | 
					            b" object-src 'self';",
 | 
				
			||||||
        )
 | 
					        )
 | 
				
			||||||
 | 
					        request.setHeader(
 | 
				
			||||||
 | 
					            b"Referrer-Policy", b"no-referrer",
 | 
				
			||||||
 | 
					        )
 | 
				
			||||||
        server_name, media_id, name = parse_media_id(request)
 | 
					        server_name, media_id, name = parse_media_id(request)
 | 
				
			||||||
        if server_name == self.server_name:
 | 
					        if server_name == self.server_name:
 | 
				
			||||||
            await self.media_repo.get_local_media(request, media_id, name)
 | 
					            await self.media_repo.get_local_media(request, media_id, name)
 | 
				
			||||||
| 
						 | 
					
 | 
				
			||||||
		Loading…
	
		Reference in New Issue