[tor-bugs] #32865 [Applications/Tor Browser]: Setting Origin: null header still breaks CORS in Tor Browser 9.5

Tor Bug Tracker & Wiki blackhole at torproject.org
Fri Jan 3 17:10:35 UTC 2020


#32865: Setting Origin: null header still breaks CORS in Tor Browser 9.5
--------------------------------------+--------------------------
 Reporter:  micahlee                  |          Owner:  tbb-team
     Type:  defect                    |         Status:  new
 Priority:  Medium                    |      Milestone:
Component:  Applications/Tor Browser  |        Version:
 Severity:  Normal                    |     Resolution:
 Keywords:                            |  Actual Points:
Parent ID:                            |         Points:
 Reviewer:                            |        Sponsor:
--------------------------------------+--------------------------

Comment (by gk):

 Replying to [ticket:32865 micahlee]:

 [snip]

 > One possible solution would be to treat onion sites that load resources
 from other onion sites different than onion sites loading resources from
 clearnet sites. When it's onion -> onion, it could send the actual
 `Referer` and `Origin` headers, but when it's onion -> clearnet, it could
 strip the `Referer` header and send `Origin: null`, which is the current
 behavior.

 On the positive side, I think this seems to be worth exploring to me
 (bonus points if we have a convincing argument as to why this is (still)
 spec-compliant).

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/32865#comment:5>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list