[Django] #29406: Add Referrer-Policy header support

classic Classic list List threaded Threaded
7 messages Options
Reply | Threaded
Open this post in threaded view
|

[Django] #29406: Add Referrer-Policy header support

Django
#29406: Add Referrer-Policy header support
-----------------------------------------+-------------------------------
               Reporter:  James Bennett  |          Owner:  James Bennett
                   Type:  New feature    |         Status:  assigned
              Component:  Utilities      |        Version:  master
               Severity:  Normal         |       Keywords:
           Triage Stage:  Accepted       |      Has patch:  0
    Needs documentation:  0              |    Needs tests:  0
Patch needs improvement:  0              |  Easy pickings:  0
                  UI/UX:  0              |
-----------------------------------------+-------------------------------
 Background information on django-dev list:

 https://groups.google.com/forum/#!topic/django-developers/DDpkrvFdnvk

 Other parts of that proposal still need work, but Referrer-Policy seemed
 to have consensus to go ahead and do.

--
Ticket URL: <https://code.djangoproject.com/ticket/29406>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.

--
You received this message because you are subscribed to the Google Groups "Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [hidden email].
To post to this group, send email to [hidden email].
To view this discussion on the web visit https://groups.google.com/d/msgid/django-updates/054.a0733365e8e20cc38b66a91817de4362%40djangoproject.com.
For more options, visit https://groups.google.com/d/optout.
Reply | Threaded
Open this post in threaded view
|

Re: [Django] #29406: Add Referrer-Policy header support

Django
#29406: Add Referrer-Policy header support
-------------------------------+-----------------------------------------
     Reporter:  James Bennett  |                    Owner:  James Bennett
         Type:  New feature    |                   Status:  assigned
    Component:  Utilities      |                  Version:  master
     Severity:  Normal         |               Resolution:
     Keywords:                 |             Triage Stage:  Accepted
    Has patch:  0              |      Needs documentation:  0
  Needs tests:  0              |  Patch needs improvement:  0
Easy pickings:  0              |                    UI/UX:  0
-------------------------------+-----------------------------------------

Comment (by James Bennett):

 I'm going to leave this on hold for now. I'm currently supporting the
 feature via a third-party app (django-referrer-policy), and I want to work
 out the issues with browser support there, rather than burden Django
 itself with them. Once that's figured out, I'll contribute the code back
 to Django.

--
Ticket URL: <https://code.djangoproject.com/ticket/29406#comment:1>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.

--
You received this message because you are subscribed to the Google Groups "Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [hidden email].
To post to this group, send email to [hidden email].
To view this discussion on the web visit https://groups.google.com/d/msgid/django-updates/069.9dc868c275f6fa5e7855b48eef8e93cb%40djangoproject.com.
For more options, visit https://groups.google.com/d/optout.
Reply | Threaded
Open this post in threaded view
|

Re: [Django] #29406: Add Referrer-Policy header support

Django
In reply to this post by Django
#29406: Add Referrer-Policy header support
-------------------------------+-----------------------------------------
     Reporter:  James Bennett  |                    Owner:  James Bennett
         Type:  New feature    |                   Status:  assigned
    Component:  Utilities      |                  Version:  master
     Severity:  Normal         |               Resolution:
     Keywords:                 |             Triage Stage:  Someday/Maybe
    Has patch:  0              |      Needs documentation:  0
  Needs tests:  0              |  Patch needs improvement:  0
Easy pickings:  0              |                    UI/UX:  0
-------------------------------+-----------------------------------------
Changes (by James Bennett):

 * stage:  Accepted => Someday/Maybe


--
Ticket URL: <https://code.djangoproject.com/ticket/29406#comment:2>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.

--
You received this message because you are subscribed to the Google Groups "Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [hidden email].
To post to this group, send email to [hidden email].
To view this discussion on the web visit https://groups.google.com/d/msgid/django-updates/069.af6b7f241aac5108403ca0d400872ba6%40djangoproject.com.
For more options, visit https://groups.google.com/d/optout.
Reply | Threaded
Open this post in threaded view
|

Re: [Django] #29406: Add Referrer-Policy header support

Django
In reply to this post by Django
#29406: Add Referrer-Policy header support
-------------------------------+-----------------------------------------
     Reporter:  James Bennett  |                    Owner:  James Bennett
         Type:  New feature    |                   Status:  assigned
    Component:  Utilities      |                  Version:  master
     Severity:  Normal         |               Resolution:
     Keywords:                 |             Triage Stage:  Accepted
    Has patch:  1              |      Needs documentation:  0
  Needs tests:  0              |  Patch needs improvement:  0
Easy pickings:  0              |                    UI/UX:  0
-------------------------------+-----------------------------------------
Changes (by Claude Paroz):

 * has_patch:  0 => 1
 * stage:  Someday/Maybe => Accepted


Comment:

 I reopened a [https://github.com/django/django/pull/11732 PR] based on
 James initial work.
 I hope that in conjunction with #30426, this would mean a more secure
 Django 3.0 by default.

--
Ticket URL: <https://code.djangoproject.com/ticket/29406#comment:3>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.

--
You received this message because you are subscribed to the Google Groups "Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [hidden email].
To view this discussion on the web visit https://groups.google.com/d/msgid/django-updates/069.4921c020069aa5f4d22da2faf79278fc%40djangoproject.com.
Reply | Threaded
Open this post in threaded view
|

Re: [Django] #29406: Add Referrer-Policy header support

Django
In reply to this post by Django
#29406: Add Referrer-Policy header support
-------------------------------+-----------------------------------------
     Reporter:  James Bennett  |                    Owner:  James Bennett
         Type:  New feature    |                   Status:  assigned
    Component:  Utilities      |                  Version:  master
     Severity:  Normal         |               Resolution:
     Keywords:                 |             Triage Stage:  Accepted
    Has patch:  1              |      Needs documentation:  0
  Needs tests:  0              |  Patch needs improvement:  0
Easy pickings:  0              |                    UI/UX:  0
-------------------------------+-----------------------------------------

Comment (by Claude Paroz):

 My PR was closed in favor of the
 [https://github.com/django/django/pull/11735 one from Nick].

--
Ticket URL: <https://code.djangoproject.com/ticket/29406#comment:4>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.

--
You received this message because you are subscribed to the Google Groups "Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [hidden email].
To view this discussion on the web visit https://groups.google.com/d/msgid/django-updates/069.c397be9dc23dce00486f78c658eb07b9%40djangoproject.com.
Reply | Threaded
Open this post in threaded view
|

Re: [Django] #29406: Add Referrer-Policy header support

Django
In reply to this post by Django
#29406: Add Referrer-Policy header support
-------------------------------------+-------------------------------------
     Reporter:  James Bennett        |                    Owner:  James
                                     |  Bennett
         Type:  New feature          |                   Status:  assigned
    Component:  Utilities            |                  Version:  master
     Severity:  Normal               |               Resolution:
     Keywords:                       |             Triage Stage:  Ready for
                                     |  checkin
    Has patch:  1                    |      Needs documentation:  0
  Needs tests:  0                    |  Patch needs improvement:  0
Easy pickings:  0                    |                    UI/UX:  0
-------------------------------------+-------------------------------------
Changes (by Carlton Gibson):

 * stage:  Accepted => Ready for checkin


--
Ticket URL: <https://code.djangoproject.com/ticket/29406#comment:5>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.

--
You received this message because you are subscribed to the Google Groups "Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [hidden email].
To view this discussion on the web visit https://groups.google.com/d/msgid/django-updates/069.25b6f5c95038c1f4c902ff88e6fb0d5a%40djangoproject.com.
Reply | Threaded
Open this post in threaded view
|

Re: [Django] #29406: Add Referrer-Policy header support

Django
In reply to this post by Django
#29406: Add Referrer-Policy header support
-------------------------------------+-------------------------------------
     Reporter:  James Bennett        |                    Owner:  James
                                     |  Bennett
         Type:  New feature          |                   Status:  closed
    Component:  Utilities            |                  Version:  master
     Severity:  Normal               |               Resolution:  fixed
     Keywords:                       |             Triage Stage:  Ready for
                                     |  checkin
    Has patch:  1                    |      Needs documentation:  0
  Needs tests:  0                    |  Patch needs improvement:  0
Easy pickings:  0                    |                    UI/UX:  0
-------------------------------------+-------------------------------------
Changes (by Carlton Gibson <carlton.gibson@…>):

 * status:  assigned => closed
 * resolution:   => fixed


Comment:

 In [changeset:"406dba04e1482a308cad74e3d06c050c76ba2d16" 406dba04]:
 {{{
 #!CommitTicketReference repository=""
 revision="406dba04e1482a308cad74e3d06c050c76ba2d16"
 Fixed #29406 -- Added support for Referrer-Policy header.

 Thanks to James Bennett for the initial implementation.
 }}}

--
Ticket URL: <https://code.djangoproject.com/ticket/29406#comment:6>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.

--
You received this message because you are subscribed to the Google Groups "Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [hidden email].
To view this discussion on the web visit https://groups.google.com/d/msgid/django-updates/069.e974bade88b13ee1225cdd6dfa9e69fb%40djangoproject.com.