Security
What is set on every response, what a password actually achieves, and the two places where a request is refused rather than answered.
Response headers
X-Frame-Options: SAMEORIGINX-Content-Type-Options: nosniffReferrer-Policy: strict-origin-when-cross-originReferer header when you follow a short link from a page with a slug in it.Strict-Transport-SecurityCross-Origin-Opener-Policy was set and then removed. It made same-origin iframes unreadable, and nothing on this site needed it. Leaving it would have broken the tools page for no security gain.
Why preview refuses some addresses
/api/preview fetches an address you give it. Left alone, that is a way to ask a server to reach things only it can reach: a loopback service, or something on a private network behind it.
So the address is checked before the fetch happens, not after:
- A host that resolves to a private, loopback or otherwise reserved range is refused with
reason: private. - A port that is not an ordinary one is refused with
reason: port. - A host that is not usable at all is refused with
reason: host.
An address that is merely unreachable is not refused. That comes back 200 with empty fields, because "I could not get there" is an answer and not a failure. If every unreachable address were an error, the endpoint would be a way to test whether a given host exists.
What a password gate does
A gate stops somebody following a link from arriving at the destination without typing a word. Specifically:
- The response for a protected link is the gate, at status
200, and it contains no part of the destination. - Only a SHA-256 digest of the password is stored. The password itself is never written anywhere.
- The unlock cookie is
HttpOnly, so a script on the page cannot read it;SameSite=Lax;Secure, so it is not sent over plain HTTP; and it expires with the link. - Attempts are capped at twelve a minute per address.
What it does not do
For the same reason, a password is not a claim on who may delete a link. Removal needs no password, because the password protects the redirect from the public, not the record from its owner.
What is not collected
- No analytics of any kind, on any page.
- No account, so nothing to attach a visit to.
- No cookie other than the unlock cookie on a protected link. Nothing is set for an ordinary short link.
- No IP addresses beyond the rate-limit counter, which is a number in a key that expires within a couple of minutes.
- Nothing about who clicked, beyond what the storage page lists.