[wp-trac] [WordPress Trac] #43285: The default admin referrer policy header value block the access to media on other server in admin panel

WordPress Trac noreply at wordpress.org
Mon Mar 12 10:56:55 UTC 2018


#43285: The default admin referrer policy header value block the access to media on
other server in admin panel
-------------------------+-----------------------------
 Reporter:  qcmiao       |       Owner:  johnbillion
     Type:  enhancement  |      Status:  closed
 Priority:  normal       |   Milestone:  4.9.5
Component:  Security     |     Version:  4.9
 Severity:  normal       |  Resolution:  fixed
 Keywords:  has-patch    |     Focuses:  administration
-------------------------+-----------------------------
Changes (by johnbillion):

 * status:  reviewing => closed
 * resolution:   => fixed


Comment:

 In [changeset:"42830"]:
 {{{
 #!CommitTicketReference repository="" revision="42830"
 Security: Loosen the admin referrer policy header value to allow the
 referring host to be sent from the admin area in all cases.

 This allows referrer-restricted content from third parties (such as images
 and fonts) to continue working in the admin area.

 Props aranwer104, qcmiao

 Fixes #43285
 }}}

--
Ticket URL: <https://core.trac.wordpress.org/ticket/43285#comment:7>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list