Print Dialog not passing referrer or origin headers

Not reproducible Issue #23385758

Details

Author
Drew W.
Created
Sep 4, 2019
Privacy
This issue is public.
Found in
  • Microsoft Edge
Reports
Reported by 1 person

Sign in to watch or report this issue.

Steps to reproduce

We have a page that calls an API to return an image. As part of our CSRF protection, we expect the origin or referrer header to be present otherwise we return a 403.

Our product dynamically creates a webpage report and utilises the print function of the browser. In Edge, when you click the print button, the print dialogue appears the request for the images are resent but without the referrer or origin headers, thus our CSRF middleware rejects the request.

Can the print dialogue send the referrer header please?

Attachments

0 attachments

    Comments and activity

    • Microsoft Edge Team

      Changed Assigned To to “Zachariah L.”

    • Hi Drew!

      Thank you for contacting us! Is this a feature request?

      Thanks,

      Zach

    • Hi!

      For now, I will resolve this issue as "Not Reproducible". Feel free to reopen this issue with the information requested.

      Thanks,

      Zach

    • Microsoft Edge Team

      Changed Status to “Not reproducible”

    You need to sign in to your Microsoft account to add a comment.

    Sign in