I understand relying on Referer in the request header is not right. But my question is, why IE does not set Referer to the Request Header if I use window.location
? Any thoughts or fixes?
This does not set Referer in the Request header:
function load1() {
window.location = "https://" + serverURL + "/path/folder/page.aspx";
}
<a href="javascript:load1()">Link 1</a>
While this sets:
<a href="https://hardcode.server.url/path/folder/page.aspx">Link 1</a>
Your post title shows that you want to change the current page programmatically using JavaScript but still having the HTTP referrer provided (from what I understood, using a <a>
tag is just for a test case).
You need to be aware of cross-browser issues:
window.location.href
under the following browsers:
window.location.href
(this is why some pseudo-solutions are based on myLink.click()
)click
function does not exist (this is why pseudo-solutions based on myLink.click()
do not work)click
function exists under Firefox 5 but does not
change the window location, so all the methods relying on the
existence of the myLink.click()
method will not work. Calling myLink.onclick()
or myLink.onClick()
raise an error ("onclick is not a function"), so solutions based on these calls will not work.In order to manage these cross-browser issues, I'm using the following method:
function navigateToUrl(url) {
var f = document.createElement("FORM");
f.action = url;
var indexQM = url.indexOf("?");
if (indexQM>=0) {
// the URL has parameters => convert them to hidden form inputs
var params = url.substring(indexQM+1).split("&");
for (var i=0; i<params.length; i++) {
var keyValuePair = params[i].split("=");
var input = document.createElement("INPUT");
input.type="hidden";
input.name = keyValuePair[0];
input.value = keyValuePair[1];
f.appendChild(input);
}
}
document.body.appendChild(f);
f.submit();
}
navigateToUrl("http://foo.com/bar");
This solution works on all the browser flavors and version listed above. It has the advantage to be simple, multi-browser and easy to understand. Note that this has not been tested under HTTPS.