gerrit/resources
Logan Hanks dbde9244fe Set "never" referrer policy
Linkification and plugins can cause requests originating from PolyGerrit
to third-party sites. Without this policy, such requests would include a
"Referer" header that potentially reveals sensitive information in
hostnames, project names, and filenames.

Unfortunately, different browsers implement different versions of the
standard. We want to use the legacy policy name "never" so browsers that
only implement the legacy standard will comply. We use a meta tag
instead of an HTTP response header because Chrome doesn't respect legacy
policies specified outside of meta tags.

Change-Id: Ibb601742121c6d0c9122e34dda2d447a068c0913
2018-11-01 14:48:22 -07:00
..
com/google/gerrit Set "never" referrer policy 2018-11-01 14:48:22 -07:00
BUILD Dissolve gerrit-war top-level directory 2017-10-31 11:02:37 -04:00
log4j.properties Dissolve gerrit-war top-level directory 2017-10-31 11:02:37 -04:00