Why does Launchpad require a Referer header?

Created by Gary Poster on on 2010-03-26
Keywords:
Referer referrer
Last updated by:
William Grant on on 2011-04-11

Launchpad enforces the presence of Referer headers in browser POST requests.

The reason for this is to address an important web-site attack vector, cross-site request forgery.

http://en.wikipedia.org/wiki/Cross-site_request_forgery

Therefore, to work with Launchpad, you will need to let your browser send Launchpad your Referer headers.

If you are using Firefox and wish to send your Referer header only to certain sites, there appears to be at least one Firefox add-on that does what you want. People have reported success with it. That said, we do not know anything about it except for its description and reviews. https://addons.mozilla.org/en-US/firefox/addon/953