ãªã Origin ãå¿ è¦ãªã®ã§ããã?
æãããåç¥ã®éããHTTP ãããã«ã¯ Referer ãããã¾ããããã¯é常ããããã¯ã¼ã¯ãªã¯ã¨ã¹ããéå§ãããã¼ã¸ã® URL ãå«ã¾ãã¦ãã¾ãã
ä¾ãã°ãhttp://javascript.info/some/url ãã http://google.com ãåå¾ãããã¨ããã¨ããã®ãããã¯æ¬¡ã®ããã«ãªãã¾ãã:
Accept: */*
Accept-Charset: utf-8
Accept-Encoding: gzip,deflate,sdch
Connection: keep-alive
Host: google.com
Origin: http://javascript.info
Referer: http://javascript.info/some/url
ã覧ã®éããReferer 㨠Origin 両æ¹ãåå¨ãã¾ãã
ããã§è³ªåã§ã:
Refererãããå¤ãã®æ å ±ãæã£ã¦ããã®ã«ããªãOriginãå¿ è¦ãªã®ã§ãããããRefererãOriginããªãããããã¯ãããæ£ãããªãå¯è½æ§ã¯ããã¾ããï¼
Origin ã¯å¿
è¦ã§ãããªããªããReferer ã¯ãªãå ´åãããããã§ããä¾ãã°ãHTTPS ã§ HTTP ã®ãã¼ã¸ã fetch ããã¨ã(ããã»ãã¥ã¢ãªå ´æããã»ãã¥ã¢ã§ãªãå ´æã¸ã¢ã¯ã»ã¹ããã¨ã)ãReferer ã¯ããã¾ããã
ã³ã³ãã³ãã»ãã¥ãªãã£ããªã·ã¼(Content Security Policy: CSP) 㯠Referer ãéä¿¡ããã®ãç¦æ¢ããå¯è½æ§ãããã¾ãã
å¾ã»ã©åããã¾ãããfetch ã«ã Referer ã®éä¿¡ãé²ãã ããããã夿´ãããã¨ã許å¯ãã(åããµã¤ãå
ã§)ãªãã·ã§ã³ãããã¾ãã
仿§ã«ããã¨ãReferer ã¯ãªãã·ã§ã³ã® HTTP ãããã§ãã
Referer ã¯ä¿¡é ¼ã§ããªããããOrigin ãçºæããã¾ããããã©ã¦ã¶ã¯ã¯ãã¹ãªãªã¸ã³ãªã¯ã¨ã¹ãã®ããã«ãæ£ãã Origin ãä¿è¨¼ãã¾ãã