You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

跨域(sec-fetch-site为cross-site)下Chrome获取完整Referer URL方案

Fixing Truncated Referer in Chrome/Edge Cross-Site Login Redirects

Got it, let's tackle this frustrating Referer issue with Chrome and Edge's recent policy changes. I've dealt with similar scenarios when handling cross-domain login flows, so here are straightforward, actionable fixes across JavaScript, JSP, and Java layers that should resolve your problem:

1. Frontend JavaScript: Pass Original URL as a Query Parameter (Most Reliable)

Since browser policies are restricting full Referer in cross-site contexts, the simplest workaround is to explicitly pass the original page URL as a query parameter when redirecting. This bypasses Referer limitations entirely and works across all browsers.

Example Code:

// For programmatic redirects
function redirectToClientLogin() {
  const originalPageUrl = encodeURIComponent(window.location.href);
  const clientLoginUrl = `https://your-client-site.com/login?originalReferrer=${originalPageUrl}`;
  window.location.href = clientLoginUrl;
}

// For static links (dynamically set href)
document.addEventListener('DOMContentLoaded', () => {
  const loginLink = document.getElementById('client-login-link');
  if (loginLink) {
    const originalUrl = encodeURIComponent(window.location.href);
    loginLink.href = `https://your-client-site.com/login?originalReferrer=${originalUrl}`;
  }
});

How it works:

Your client's site can then extract the originalReferrer parameter from the request URL instead of relying on the Referer header. No browser policy will block this, and it’s compatible with Firefox, IE, Chrome, Edge—all of them.

2. Backend Java/JSP: Adjust Referrer-Policy Header

If you prefer to keep using the Referer header, you can set a Referrer-Policy response header on your origin site to instruct Chrome/Edge to send the full URL even in cross-site scenarios. Note that this has security tradeoffs, so evaluate based on your use case.

JSP Example:

<%
// Add this at the top of your JSP page
response.setHeader("Referrer-Policy", "unsafe-url");
%>

Java Servlet/Spring Example:

// In a Servlet's doGet/doPost method
protected void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
    response.setHeader("Referrer-Policy", "unsafe-url");
    // Rest of your logic
}

// For Spring Boot (add to a controller or filter)
@GetMapping("/your-redirect-page")
public String redirectToClient(HttpServletResponse response) {
    response.setHeader("Referrer-Policy", "unsafe-url");
    return "redirect:https://your-client-site.com/login";
}

Caveat:

The unsafe-url value will send the full URL (including path, query params) in cross-site Referer headers. If your page URLs contain sensitive information (like session IDs or user data), this could expose that data to the client site. Use this only if you trust the client and your URLs don’t have sensitive data.

3. Additional Notes

  • If you’re using a reverse proxy (like Nginx), you can also set the Referrer-Policy header there instead of in your application code—this is handy if you don’t want to modify Java/JSP/JS code.
  • Always URL-encode the original URL when passing it as a parameter to avoid parsing issues with special characters.

内容的提问来源于stack exchange,提问作者Ankit

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 20:07:41