Set a Referrer-Policy header
headers-referrer
The Referer header sends your full URL to every site you link out to. A Referrer-Policy trims it so tokens and IDs in the path do not leak.
CDN and edge
Web servers
Frameworks
Cloudflare
- 1 Go to Rules > Transform Rules > Modify Response Header
- 2 Create a rule that sets Referrer-Policy to the desired value
- 3 Deploy the rule
Header name: Referrer-Policy
Value: strict-origin-when-cross-originAWS CloudFront
- 1 Create a Response Headers Policy in CloudFront
- 2 Attach the policy to your distribution's behavior
Custom header:
Name: Referrer-Policy
Value: strict-origin-when-cross-origin
Override origin: YesVercel
- 1 Add a headers entry to your vercel.json
- 2 Redeploy
json
{
"headers": [
{
"source": "/(.*)",
"headers": [
{ "key": "Referrer-Policy", "value": "strict-origin-when-cross-origin" }
]
}
]
}Netlify
- 1 Add a headers section to your netlify.toml or _headers file
- 2 Redeploy
toml
[[headers]]
for = "/*"
[headers.values]
Referrer-Policy = "strict-origin-when-cross-origin"Nginx
- 1 Add the header directive to your server or location block
- 2 Test config with nginx -t, then reload
nginx
add_header Referrer-Policy "strict-origin-when-cross-origin" always;Apache
- 1 Make sure mod_headers is enabled
- 2 Add the Header directive to your .htaccess or VirtualHost
apacheconf
Header always set Referrer-Policy "strict-origin-when-cross-origin"Caddy
- 1 Add a header directive to your Caddyfile
- 2 Reload Caddy
caddyfile
header Referrer-Policy "strict-origin-when-cross-origin"Next.js
- 1 Add a headers function to your next.config.js
- 2 Rebuild and redeploy
javascript
// next.config.js
module.exports = {
async headers() {
return [{
source: "/(.*)",
headers: [
{ key: "Referrer-Policy", value: "strict-origin-when-cross-origin" },
],
}];
},
};Express
- 1 Use the helmet middleware (recommended) or set the header manually
- 2 Restart your server
javascript
// Using helmet (recommended)
const helmet = require("helmet");
app.use(helmet());
// Or manually
app.use((req, res, next) => {
res.setHeader("Referrer-Policy", "strict-origin-when-cross-origin");
next();
});Django
- 1 Set the Referrer-Policy in settings.py
python
# settings.py
SECURE_REFERRER_POLICY = 'strict-origin-when-cross-origin'Laravel
- 1 Add a middleware that sets the header
- 2 Register it in your HTTP kernel
php
// app/Http/Middleware/SecurityHeaders.php
public function handle($request, Closure $next)
{
$response = $next($request);
$response->headers->set('Referrer-Policy', 'strict-origin-when-cross-origin');
return $response;
}Rails
- 1 Set the header in your ApplicationController or config
ruby
# config/application.rb
config.action_dispatch.default_headers.merge!(
'Referrer-Policy' => 'strict-origin-when-cross-origin'
)Spring Boot
- 1 Configure the header in your SecurityFilterChain
java
@Bean
SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
http.headers(h -> h
.addHeaderWriter(new StaticHeadersWriter("Referrer-Policy", "strict-origin-when-cross-origin"))
);
return http.build();
}WordPress
- 1 Add the header via your theme's functions.php or .htaccess
- 2 A security plugin like HTTP Headers can also help
php
# .htaccess (Apache)
Header always set Referrer-Policy "strict-origin-when-cross-origin"
# Or in functions.php
add_action('send_headers', function() {
header('Referrer-Policy: strict-origin-when-cross-origin');
});Nuxt
- 1 Add the header to your nuxt.config.ts routeRules
- 2 Rebuild and redeploy
typescript
// nuxt.config.ts
export default defineNuxtConfig({
routeRules: {
'/**': {
headers: { 'Referrer-Policy': 'strict-origin-when-cross-origin' },
},
},
});ASP.NET
- 1 Add middleware in your Program.cs or Startup.cs
csharp
app.Use(async (context, next) =>
{
context.Response.Headers.Append("Referrer-Policy", "strict-origin-when-cross-origin");
await next();
});Does your app still have this?
Scan your domain