<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does strict Referrer policy impact RUM? in Real User Monitoring</title>
    <link>https://community.dynatrace.com/t5/Real-User-Monitoring/Does-strict-Referrer-policy-impact-RUM/m-p/178841#M3477</link>
    <description>&lt;P&gt;As always the answer is "it depends".&lt;/P&gt;&lt;P&gt;There are many factors influencing the outcome:&lt;/P&gt;&lt;P&gt;* Are they using https(i am guessing they do)&lt;/P&gt;&lt;P&gt;* Are we talking about newer browsers which have Server-Timing API support?&lt;/P&gt;&lt;P&gt;* Do they use older jsagent versions and aws lambda support?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In general we have improved a few things recently with aws lambda support to make it work. There are however some limitations where we do need the referer to properly correlate a webrequest to an action. This is mostly the case when loading e.g. images during an action, because the request is triggered entirely by the browser and we can not modify the information on those requests. Those might not be correlated(see above list), because we can not 100% be sure that they match to an action and we'd rather not correlate them than correlate them wrong.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So the best thing is probably to try it out and see if it affects the customer in a way that is acceptable or not. But as always with almost all security relevant changes: If you get rid of data, you might also get rid of functionality.&lt;/P&gt;</description>
    <pubDate>Tue, 18 Jan 2022 15:38:56 GMT</pubDate>
    <dc:creator>simon_schatka</dc:creator>
    <dc:date>2022-01-18T15:38:56Z</dc:date>
    <item>
      <title>Does strict Referrer policy impact RUM?</title>
      <link>https://community.dynatrace.com/t5/Real-User-Monitoring/Does-strict-Referrer-policy-impact-RUM/m-p/176926#M3267</link>
      <description>&lt;P&gt;We have a customer that uses an external authentication service.&lt;BR /&gt;&lt;BR /&gt;The external party did an audit which showed that the customer's&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&amp;nbsp;Referrer Policy has a vulnerability.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Forwarding of referrer URLs from customer's closed domains is no longer desirable and therefore they need to stop this.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;The referrer policy will have the value 'no-referrer' or 'same-origin' (see &lt;A href="https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy" target="_blank" rel="noopener"&gt;https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;The question is if adjusting this setting may have consequences for the functioning of Dynatrace. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Currently they use Agentless RUM, manually injected. Where for example "app.customer.domain" is where the injection takes place, and&amp;nbsp; RUM data is sent to "activegate.customer.domain".&lt;BR /&gt;&lt;BR /&gt;I happen to think that the change in Referrer policy has no direct effect on Dynatrace RUM. Dynatrace is great in detecting and measuring the use of referrers. But I want to be absolutely sure this has not impact.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Dec 2021 14:57:34 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Real-User-Monitoring/Does-strict-Referrer-policy-impact-RUM/m-p/176926#M3267</guid>
      <dc:creator>fstekelenburg</dc:creator>
      <dc:date>2021-12-03T14:57:34Z</dc:date>
    </item>
    <item>
      <title>Re: Does strict Referrer policy impact RUM?</title>
      <link>https://community.dynatrace.com/t5/Real-User-Monitoring/Does-strict-Referrer-policy-impact-RUM/m-p/178841#M3477</link>
      <description>&lt;P&gt;As always the answer is "it depends".&lt;/P&gt;&lt;P&gt;There are many factors influencing the outcome:&lt;/P&gt;&lt;P&gt;* Are they using https(i am guessing they do)&lt;/P&gt;&lt;P&gt;* Are we talking about newer browsers which have Server-Timing API support?&lt;/P&gt;&lt;P&gt;* Do they use older jsagent versions and aws lambda support?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In general we have improved a few things recently with aws lambda support to make it work. There are however some limitations where we do need the referer to properly correlate a webrequest to an action. This is mostly the case when loading e.g. images during an action, because the request is triggered entirely by the browser and we can not modify the information on those requests. Those might not be correlated(see above list), because we can not 100% be sure that they match to an action and we'd rather not correlate them than correlate them wrong.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So the best thing is probably to try it out and see if it affects the customer in a way that is acceptable or not. But as always with almost all security relevant changes: If you get rid of data, you might also get rid of functionality.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jan 2022 15:38:56 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Real-User-Monitoring/Does-strict-Referrer-policy-impact-RUM/m-p/178841#M3477</guid>
      <dc:creator>simon_schatka</dc:creator>
      <dc:date>2022-01-18T15:38:56Z</dc:date>
    </item>
  </channel>
</rss>

