How to get correct URL in HTTP header?

What's wrong with using the HTTP refer(r)er header to determine the URL of the page containing an <iframe>?

  • That is, why can't the server responding to the <iframe>'s HTTP request trust the HTTP_REFERER of that request?  Even if some user agents don't send it, at least the containing site doesn't have any control over the header. This is a follow-up question to .

  • Answer:

    The http referer header can easily be spoofed and cannot be used for any security decisions.

Miguel Paraz at Quora Visit the source

Was this solution helpful to you?

Related Q & A:

Just Added Q & A:

Find solution

For every problem there is a solution! Proved by Solucija.

  • Got an issue and looking for advice?

  • Ask Solucija to search every corner of the Web for help.

  • Get workable solutions and helpful tips in a moment.

Just ask Solucija about an issue you face and immediately get a list of ready solutions, answers and tips from other Internet users. We always provide the most suitable and complete answer to your question at the top, along with a few good alternatives below.