“Referrer-Policy: no-referrer”
-
“Referrer-Policy: no-referrer” is set at our server/hosting level, which I think is the strictest and is set to keep things as secure as possible (if you disagree be great to hear why and if there’s a better setting we could request that other WP site owners use).
This setting prevents core WP password protect pages from working. When you enter the password the user sees the white PHP screen with no error. I presume the WordPress password protect page needs the referrer? Should it really be using some kind of redirect instead? We proved this by amending /removing the Referrer-policy and the password page functionality worked.
I found another password protected page plugin called “content-protector” which I tested and it gets around this problem (it must use an alternative to referrer). However, I am hoping I can find a way to make the core WordPress and config work rather than relying on another plugin.
TIA, P26
- You must be logged in to reply to this topic.