400 - Bad Referer header
Checklist
- I confirm that this is an issue with aurweb's code and not a user-uploaded package.
- I have described the bug in complete detail in the Description section.
- I have specified steps in the Reproduction section.
- I have included any logs related to the bug in the Logs section.
- I have included the versions which are affected in the Version(s) section.
Description
Disabling referer headers in browser breaks aurweb login, and redirects to 400 page saying Bad Referer header
Reproduction
- Open firefox and set config
network.http.sendRefererHeader=0
- Go to https://aur.archlinux.org/login
- Attempt to login
Logs
N/A
Version(s)
aurweb v6.0.19