From c8daa1421960a1bd37d2e87684a20b308f544105 Mon Sep 17 00:00:00 2001 From: saopig1 <4x7sw862st@gmail.com> Date: Wed, 27 May 2026 20:07:18 +0800 Subject: [PATCH] =?UTF-8?q?fix(web):=20set=20no-referrer=20at=20document?= =?UTF-8?q?=20level=20so=20B=E7=AB=99=20cover=20thumbnails=20load?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Bilibili's CDN (i*.hdslb.com) returns 403 with `x-error-info: RefererWhite` for image requests whose Referer is not on their whitelist. `CoverArt.vue` already sets `referrerpolicy="no-referrer"` on its `` tag, BUT the `.cover-shadow` div renders the same URL as a CSS `background-image`, which ignores the img attribute and uses the document default policy (`strict-origin-when-cross-origin` in modern Firefox/Chrome) — that sends `Referer: http://localhost:3000/` and triggers the block. Setting `` in index.html applies no-referrer site-wide: covers tags, CSS background-image fetches, and anywhere else CDNs check referer. Doesn't affect our /api/* CSRF middleware because that uses Origin (still sent by the browser), not Referer. Co-Authored-By: Claude Opus 4.7 (1M context) --- web/index.html | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/web/index.html b/web/index.html index 8ae625d..bf7535c 100644 --- a/web/index.html +++ b/web/index.html @@ -3,6 +3,10 @@ + + TSMusicBot