From c8daa1421960a1bd37d2e87684a20b308f544105 Mon Sep 17 00:00:00 2001
From: saopig1 <4x7sw862st@gmail.com>
Date: Wed, 27 May 2026 20:07:18 +0800
Subject: [PATCH] =?UTF-8?q?fix(web):=20set=20no-referrer=20at=20document?=
=?UTF-8?q?=20level=20so=20B=E7=AB=99=20cover=20thumbnails=20load?=
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Bilibili's CDN (i*.hdslb.com) returns 403 with `x-error-info:
RefererWhite` for image requests whose Referer is not on their
whitelist. `CoverArt.vue` already sets `referrerpolicy="no-referrer"`
on its `` tag, BUT the `.cover-shadow` div renders the same URL
as a CSS `background-image`, which ignores the img attribute and uses
the document default policy (`strict-origin-when-cross-origin` in
modern Firefox/Chrome) — that sends `Referer: http://localhost:3000/`
and triggers the block.
Setting `` in index.html
applies no-referrer site-wide: covers tags, CSS background-image
fetches, and anywhere else CDNs check referer. Doesn't affect our
/api/* CSRF middleware because that uses Origin (still sent by the
browser), not Referer.
Co-Authored-By: Claude Opus 4.7 (1M context)
---
web/index.html | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/web/index.html b/web/index.html
index 8ae625d..bf7535c 100644
--- a/web/index.html
+++ b/web/index.html
@@ -3,6 +3,10 @@
+
+
TSMusicBot