Setting custom referer in Express app before redirecting

Viewed 2521

I am working on this simple app which requires me to set custom referer value before redirecting.

Suppose A clicks on link X which I posted in Facebook. Now if I check the referer value in my server, then it shows 'facebook.com'. Now A after clicking link X is being redirected to B and B shows referer 'facebook.com'. But I want it to show 'mywebsite.com' in B instead of 'facebook.com'. How can I achieve this?

Please note that I read in MDN about the 'Forbidden Header Names' but there's this website called Hitleap which is a traffic exchange website. They let users set custom referer values for the traffic they send. So I guess it's possible to do it.

This is my route:

router.get('/:id', (req, res) => {
      res.set('Referer', 'https://mywebsite.com');
      res.redirect('https://boomboom.com');
});

UPDATE

I've found that it's not possible in conventional methods of setting the header. So, I have been thinking of achieving this result by using the following two methods but I don't know if that is going to work. So looking for feedbacks.

Method 1: So when a user clicks on my link, he will visit a page on my server before redirecting to the final destination. The page on my server will just say "redirecting". And when that happens I will also set the full header for the user, including "Referer" field. Then redirect to the actual page.

Method 2: Same approach as method 1 but this time I would like to copy the full header from the client but change the referer value when the user is in my "redirecting" page and the redirect to the final destination.

Are any of these processes possible? If you have any other solution please share it here. Thanks

1 Answers

Referer headers in the HTTP protocol go from browser to server, not the other direction. If your server sends one to a browser, the browser ignores it.

Standard commercial browsers make it hard to mess around with the value of the Referer header from browser Javascript. Because cybercreeps. Your plan might be perceived by some websites as an attempt to do a cross-site request forgery attack. So think through your goal carefully.

You could, from your site, serve a page that causes your user's browser immediately to redirect to the desired site. A page something like this may do the trick for you. This means refresh the current page after 0 seconds from the URL https://example.com.

The title tag sets the browser-tab caption to "Redirecting..." while the refresh is in progress. I've found that useful in single-signon redirection. It lets a user know something is coming.

<html>
  <head> 
    <meta http-equiv="Refresh" content="0; URL=https://example.com/">
    <title>Redirecting...</title>
  </head>
</html>

If that doesn't set the correct Referer, which it might not in all browsers, you can use a little bit of Javascript to load an invisible form and then submit it immediately.

This tiny page might do it for you:

<html>
   <head>
      <title>Redirecting...</title>
   </head>
   <body>
    <form method="GET" action="https://example.com/">
    </form> 
    <script>
       window.onload = function(){{
          document.forms[0].submit()
       }}
    </script>
  </body>
</html>

This second approach won't work if your user disables browser Javascript. But, then again, most websites won't work in that case.

You can troubleshoot all this with your browser devtools Network tab. It shows headers for each request.

Related