From a44f2f5a5773b8818a01db7228f2dc679df6e457 Mon Sep 17 00:00:00 2001 From: Mike West Date: Tue, 15 Oct 2019 08:45:11 +0200 Subject: [PATCH 1/2] Change the default referrer policy to 'strict-origin-when-cross-origin'. This addresses https://github.com/w3c/webappsec-referrer-policy/pull/125, among other things. --- fetch.bs | 5 +---- 1 file changed, 1 insertion(+), 4 deletions(-) diff --git a/fetch.bs b/fetch.bs index 6e55ecf3f..f28f2654c 100644 --- a/fetch.bs +++ b/fetch.bs @@ -3311,10 +3311,7 @@ with a CORS flag and recursive flag, run these steps:

If request's referrer policy is the empty string, then set request's referrer policy to - "no-referrer-when-downgrade". - -

We use "no-referrer-when-downgrade" because it is the - historical default. + "strict-origin-when-cross-origin".

  • If request's referrer From dd7a6621a7ce710690e1b046a4f445e4985dba34 Mon Sep 17 00:00:00 2001 From: Mike West Date: Tue, 15 Oct 2019 11:24:44 +0200 Subject: [PATCH 2/2] fixup feedback --- fetch.bs | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/fetch.bs b/fetch.bs index f28f2654c..c0ae74d15 100644 --- a/fetch.bs +++ b/fetch.bs @@ -3310,8 +3310,7 @@ with a CORS flag and recursive flag, run these steps:

  • If request's referrer policy is the empty string, then set request's - referrer policy to - "strict-origin-when-cross-origin". + referrer policy to the default referrer policy.

  • If request's referrer