Donmai

Danbooru checking for HTTP referer? Useless.

Posted under Bugs & Features

Bouowmx said:

Why do Danbooru server(s) check for HTTP referer? Clients can forge any HTTP header, rendering this check meaningless.

Clients can, but an intermediate site can't force the clients of people using that site to forge it, so someone who wants to (for example) directly inline Danbooru images on their site is prevented from doing so because most of the people viewing their site will send referrers normally. I assume there's some way around even that, but at the very least it stops people from inlining them on forums and blogs where they have less control over how the image is served.

Assuming I understand what you're saying right.

1