Skip to content
AITroveRead. Build. Understand.
Make this comfortable

HTML link referrer policy: control what a navigation reveals

Last updated: 7 Oct 20268 min read
tutorial
IntermediateBy AITrove Editorial

An anchor referrerpolicy value influences the Referer information sent when that link is followed.

Implementation choice

A support page links to a public claim glossary. The route is within the same application, yet the page may be reused when linking to another service that should not learn the current case URL. A no-referrer policy on the sensitive navigation is explicit and local to that link. It does not remove query parameters from the destination URL, hide the current page from scripts, or prevent the browser from recording history.

html
<p>Read the terminology before you submit a claim.</p>
<a href="/help/claim-terms" referrerpolicy="no-referrer">Open the claim terms</a>

What remains outside the markup

The local route must exist. A destination can still infer information from the URL being requested and from its own logs, so avoid encoding secrets in either source or destination paths.

Cost and limits

The attribute adds no separate request. The cost is policy complexity: differing link-level, document-level, and response-header rules become hard to reason about unless the application has a clear privacy policy.

Common Mistakes

  • Do not assume no-referrer anonymizes the user.
  • Do not put private tokens in the href and expect referrerpolicy to erase them.
  • Do not use link-level policy inconsistently across sensitive pages.

Connected lessons

Continue with HTML iframe referrerpolicy: limit parent-page details sent to an embed.

html
core
Storage details