跨域(sec-fetch-site为cross-site)下Chrome获取完整Referer URL方案
Got it, let's tackle this frustrating Referer issue with Chrome and Edge's recent policy changes. I've dealt with similar scenarios when handling cross-domain login flows, so here are straightforward, actionable fixes across JavaScript, JSP, and Java layers that should resolve your problem:
1. Frontend JavaScript: Pass Original URL as a Query Parameter (Most Reliable)
Since browser policies are restricting full Referer in cross-site contexts, the simplest workaround is to explicitly pass the original page URL as a query parameter when redirecting. This bypasses Referer limitations entirely and works across all browsers.
Example Code:
// For programmatic redirects function redirectToClientLogin() { const originalPageUrl = encodeURIComponent(window.location.href); const clientLoginUrl = `https://your-client-site.com/login?originalReferrer=${originalPageUrl}`; window.location.href = clientLoginUrl; } // For static links (dynamically set href) document.addEventListener('DOMContentLoaded', () => { const loginLink = document.getElementById('client-login-link'); if (loginLink) { const originalUrl = encodeURIComponent(window.location.href); loginLink.href = `https://your-client-site.com/login?originalReferrer=${originalUrl}`; } });
How it works:
Your client's site can then extract the originalReferrer parameter from the request URL instead of relying on the Referer header. No browser policy will block this, and it’s compatible with Firefox, IE, Chrome, Edge—all of them.
2. Backend Java/JSP: Adjust Referrer-Policy Header
If you prefer to keep using the Referer header, you can set a Referrer-Policy response header on your origin site to instruct Chrome/Edge to send the full URL even in cross-site scenarios. Note that this has security tradeoffs, so evaluate based on your use case.
JSP Example:
<% // Add this at the top of your JSP page response.setHeader("Referrer-Policy", "unsafe-url"); %>
Java Servlet/Spring Example:
// In a Servlet's doGet/doPost method protected void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException { response.setHeader("Referrer-Policy", "unsafe-url"); // Rest of your logic } // For Spring Boot (add to a controller or filter) @GetMapping("/your-redirect-page") public String redirectToClient(HttpServletResponse response) { response.setHeader("Referrer-Policy", "unsafe-url"); return "redirect:https://your-client-site.com/login"; }
Caveat:
The unsafe-url value will send the full URL (including path, query params) in cross-site Referer headers. If your page URLs contain sensitive information (like session IDs or user data), this could expose that data to the client site. Use this only if you trust the client and your URLs don’t have sensitive data.
3. Additional Notes
- If you’re using a reverse proxy (like Nginx), you can also set the
Referrer-Policyheader there instead of in your application code—this is handy if you don’t want to modify Java/JSP/JS code. - Always URL-encode the original URL when passing it as a parameter to avoid parsing issues with special characters.
内容的提问来源于stack exchange,提问作者Ankit

