mirror of
https://github.com/ZHANGTIANYAO1/teamspeak-music-bot.git
synced 2026-10-01 20:42:50 +08:00
Bilibili's CDN (i*.hdslb.com) returns 403 with `x-error-info: RefererWhite` for image requests whose Referer is not on their whitelist. `CoverArt.vue` already sets `referrerpolicy="no-referrer"` on its `<img>` tag, BUT the `.cover-shadow` div renders the same URL as a CSS `background-image`, which ignores the img attribute and uses the document default policy (`strict-origin-when-cross-origin` in modern Firefox/Chrome) — that sends `Referer: http://localhost:3000/` and triggers the block. Setting `<meta name="referrer" content="no-referrer">` in index.html applies no-referrer site-wide: covers <img> tags, CSS background-image fetches, and anywhere else CDNs check referer. Doesn't affect our /api/* CSRF middleware because that uses Origin (still sent by the browser), not Referer. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
19 lines
796 B
HTML
19 lines
796 B
HTML
<!DOCTYPE html>
|
|
<html lang="zh-CN">
|
|
<head>
|
|
<meta charset="UTF-8">
|
|
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
|
<!-- Bilibili / NetEase / QQ image CDNs reject requests whose Referer is not on their whitelist.
|
|
Setting no-referrer at the document level covers <img> tags AND CSS background-image fetches.
|
|
Our own /api/* CSRF check uses Origin (not Referer), so this doesn't break auth. -->
|
|
<meta name="referrer" content="no-referrer">
|
|
<title>TSMusicBot</title>
|
|
<link rel="preconnect" href="https://fonts.googleapis.com">
|
|
<link href="https://fonts.googleapis.com/css2?family=Barlow:wght@400;500;600;700;800&display=swap" rel="stylesheet">
|
|
</head>
|
|
<body>
|
|
<div id="app"></div>
|
|
<script type="module" src="/src/main.ts"></script>
|
|
</body>
|
|
</html>
|