How not to do URL redirects (… the way Quora does)
engineering.webengage.com
engineering.webengage.com
Right now they protect their users' privacy. What benefit do they realize by providing their users' viewing history to other sites?
I personally think that the referer header was never a good idea. I disable it in my browser, and appreciate sites that do right by their users with privacy protecting default behaviors.
Says who? Google and their `/url`? Facebook and their `l.php`?
On the other hand, with https and url shorteners,referers are a dying breed. The situation with URL shorteners is absurdly funny now, because twitter double-shortens the shortened urls, since most popular sites have their own shortener.
1. you need to block the click event until you get a response from your analytics endpoint. Google suggests doing this by adding a 100ms delay: http://support.google.com/googleanalytics/bin/answer.py?hl=e...
2. you might get holes in your data for a number of reasons: the user has JS turned off; 100ms isn't long enough for the request to go through; or the user might click off before your script can attach itself to the onclick event.
You definitely don't want to get yourself in a situation where you go down and all outbound links stop working, but if you can fail gracefully, replacing the link makes a lot more sense.
Incidentally, it seems that encrypted.google.com does this but not regular google. EDIT: This happens for all https->http requests, it's not a google feature (TIL).
http://nerdr.com/quora-needs-to-die/
Seems they're going down the annoying search visitors by hiding information route (similar to what expertsexchange was riled on for, although not quite as bad yet).
For example:
Say you're on this page: http://site.com/article?_uid=123 (_uid being the identity leaking query param) and clicked a link that appears to point to: http://google.com/
When a user clicks on that link, the page redirect the user to http://site.com/redirect?target=http%3A%2F%2Fgoogle.com&...
The server will then redirect the browser back to: http://site.com/article
And when the server sees that request with referrer set to /redirect?target=http%3A%2F%2Fgoogle.com, it will then parse out the target url and redirect the browser to http://google.com.
This way, the target url can be given a meaningful referrer url without compromising user's identity.
The technique I described allows Quora to customize the referrer associated with an outbound link.
<link rel="canonical" href="http://www.quora.com/What-are-everyday-apps-that-use-cloud-computing" />
They just need to update their outbound link interceptor to take that version instead of the actual url.A better title for your article would have been:
why to never rely on referers
(which can be blocked or purposely malformed)
1. Browser visits http://a.com/pages/3?privacy_leaking_param=1
2. User clicks on an outbound link: http://b.com/
3. Browser gets redirected to redirector at:
http://a.com/redirect?canonical_url=http%3A%2F%2Fa.com%2Fpages%2F3&outbound_url=http%3A%2F%2Fb.com%2F
"canonical_url" is set to "http://a.com/pages/3"
"outbound_url" is set to "http://b.com/"
4. Redirector logs the request and redirects browser to canonical_url (i.e. "http://a.com/pages/3)5. Code behind http://a.com/pages/3 checks the referrer to see if it came from the redirector.
5a. If it is, parse the outbound_url from the referrer URL and redirect the browser to that URL.
5b. If it isn't, serve normal content.
Basically, every content page needs to also act as a redirector and only redirects when the referrer indicates that the previous request came from the redirector.
www.example.com/redirect?url=http%3A%2F%2Fwww.example.net
www.example.com/redirect should record url and return 302 with Location set to www.example.net.
Another option would be to link to the real URL, and make a synchronous XHR from JavaScript (to your server) when the link is clicked.
$("a").bind("mousedown", function(e) {
$(this).data("href", $(this).attr("href"));
$(this).attr("href","http://example.com/redirect?url=" + $(this).attr("href"));
});
$("a").bind("mouseup",function(e) {
var el = $(this);
setTimeout(function() {
el.attr("href", el.data("href"));
},10);
});
This works by switching the url when a user clicks a link to your redirect url, then switching it back a fraction of a second after they mouse up. This means that your redirect works even if the user right clicks and opens in a new window / tab and when a user hovers over a link, they still see the normal URL in the status bar.On the /redirect url just log any data you need and send a 301 or 302 redirect. The destination site will see your original page as a referrer, not your redirect url.
Seems like the original link following the `url=` should be processed by encodeURIComponent or else any original urls with chars like ""&" will break.
I believe Twitter does this with URL shortener links posted in tweets.