Referrer Policy by HTTP Header
0 Intentional IssuesA page with no referrer meta tag whose policy is nonetheless declared — as a comma-separated fallback list, in the response header.
Expected result: meta_name_referrer NOT DETECTED
And referrer_policy_header (#70) not detected either. This page carries no referrer meta tag at all, which is what makes it an edge case rather than a copy of /fp-meta-referrer: a check that looks for the tag finds nothing, and a page that has declared its policy correctly gets reported.
The header this page sends
Referrer-Policy: no-referrer, strict-origin-when-cross-origin
A comma-separated list, which is what the specification defines the field value to be. A browser uses the last token it understands, so an old one falls back to no-referrer and a current one applies the recommended strict-origin-when-cross-origin. Both members are in the specification's token list; a validator that compared the whole string against that list would reject a correct header.
The three delivery routes, and which page uses each
Referrer-Policy response headerused hereSet for this path in public/_headers. The first source httpSecurityHeaders.js reads, and the one a CDN or a framework config normally owns.
<meta http-equiv="Referrer-Policy">The second source. Used by /meta-referrer-gap, which has no name tag and no header.
<meta name="referrer">The third source, and the oldest. Used by /fp-meta-referrer.
Index: /fp-edge-fixtures. The plain false-positive case is /fp-meta-referrer; the two malformed cases are /invalid-meta-referrer-empty and /invalid-meta-referrer-token.