Invalid Referrer Policy Token
0 Intentional IssuesThe referrer meta tag declares a value that is not in the specification's token list. A browser ignores it. The check does not.
Expected result: referrer_policy_header (#70) NOT DETECTED — a documented gap
This is the one page in the negative batch whose expected result is silence from a check that arguably ought to speak. The policy on this page is unusable, and #70 reports only if (!referrerPolicy) — a truthiness test on the string. No token list is consulted anywhere in the group.
It is recorded rather than fixed. Adding validation tohttpSecurityHeaders.js would be editing production detection logic so that a fixture passes. The assertion in the verification script pins the current behaviour instead, so a future change to it fails loudly.
What is declared
<meta name="referrer" content="no-referrer-when-downgrad">One character short of no-referrer-when-downgrade, which is the value the catalogue entry for #22 quotes in its own description. A truncation like this passes review and looks right in a diff, which is why it is the fixture rather than an obviously bogus string.
The specification's token list
no-referrerno-referrer-when-downgradeoriginorigin-when-cross-originsame-originstrict-originstrict-origin-when-cross-originunsafe-url
Eight tokens, and no-referrer-when-downgrad is none of them.
The pair
/invalid-meta-referrer-empty declares the same tag with an empty value and IS reported. The two pages differ in one input and disagree in their result, which is what locates the boundary at "non-empty string". /fp-meta-referrer is the valid control. Index: /malformed-fixtures.