HTML <iframe> 참조 정책 속성
예시
리퍼러 정보가 요청과 함께 전송되지 않도록 지정합니다.
<iframe src="https://w3schools.com/" referrerpolicy="no-referrer"></iframe>
정의 및 사용
이 referrerpolicy
속성은 iframe을 가져올 때 보낼 리퍼러 정보를 지정합니다.
브라우저 지원
표의 숫자는 속성을 완전히 지원하는 첫 번째 브라우저 버전을 지정합니다.
Attribute | |||||
---|---|---|---|---|---|
referrerpolicy | 51.0 | 79.0 | 50.0 | 11.1 | 38.0 |
통사론
<iframe
referrerpolicy="no-referrer|no-referrer-when-downgrade|origin|origin-when-cross-origin|same-origin|strict-origin-when-cross-origin|unsafe-url">
속성 값
Value | Description |
---|---|
no-referrer | No referrer information will be sent along with a request |
no-referrer-when-downgrade | Default. The referrer header will not be sent to origins without HTTPS |
origin | Send only scheme, host, and port to the request client |
origin-when-cross-origin | For cross-origin requests: Send only scheme, host, and port. For same-origin requests: Also include the path |
same-origin | For same-origin requests: Referrer info will be sent. For cross-origin requests: No referrer info will be sent |
strict-origin | Only send referrer info if the security level is the same (e.g. HTTPS to HTTPS). Do not send to a less secure destination (e.g. HTTPS to HTTP) |
strict-origin-when-cross-origin | Send full path when performing a same-origin request. Send only origin when the security level stays the same (e.g. HTTPS to HTTPS). Send no header to a less secure destination (HTTPS to HTTP) |
unsafe-url | Send origin, path and query string (but not fragment, password, or username). This value is considered unsafe |
❮ HTML <iframe> 태그