securityhttp-headerscross-domainhttp-refererreferrer-policy

In what cases will HTTP_REFERER be empty


I know it's possible to get an empty HTTP_REFERER. Under what circumstances does this happen? If I get an empty one, does it always mean that the user changed it? Is getting an empty one the same as getting a null one? and under what circumstances do I get that too?


Solution

  • It will/may be empty or partial when the enduser