Detailed analysis of javascript operation referer_javascript skills
Importance of Referrer
There is a referer header in the HTTP request, which is used to indicate the source reference page of the current traffic. For example, if you click a link on www.sina.com.cn/sports/ to reach the homepage of cctv.com, then the referrer will be www.sina.com.cn/sports/. In Javascript, we can get the same information through document.referrer. Through this information, we can know the channel from which visitors came to the current page. This is very important for Web Analytics. It can tell us the distribution of traffic brought by different channels, as well as the keywords searched by users, etc., which are all obtained by analyzing this referrer information.
However, for various reasons, sometimes the referrer read in Javascript is an empty string. The following summarizes the situations in which referrers will be lost.
Modify the Location object for page navigation
The Location object is a very practical object for page navigation. Because it allows you to change only part of the Url. For example, when switching from a cn domain name to a com domain name, the other parts remain unchanged:
window.location.hostname = "example.com";
However, the method of page navigation by modifying the Location will cause the Referrer to be lost under IE.
An empty string is returned under IE5.5
Chrome3.0, Firefox3.5, Opera9.6, and Safari3.2.2 all return to the source webpage normally
Open a new window with window.open method
Example:
Clicking this link will open the Google website in a new window. We can see the referrer sent by entering the following js code in the address bar.
javascript:alert(document.referrer)
Test results:
An empty string is returned under IE5.5
Chrome3.0, Firefox3.5, Opera9.6, and Safari3.2.2 all return to the source webpage normally
If the same domain name is redirected through this method, then we can obtain the lost referrer information by accessing the windoww.opener object. The code is as follows:
If it’s cross-domain, there’s no way~
Mouse drag to open a new window
Mouse drag is a very popular user habit nowadays. Many browsers have built-in or plug-in support for mouse drag browsing. However, pages opened in this way basically lose referrers. Moreover, in this case, it is impossible to use window.opener to obtain the lost referrer.
Tested:
Maxthon2.5.2, FireGesture plug-in for Firefox, Chrome3.0, Opera9.6, Safari3.2.
Click on the Flash internal link
When you click on Flash to reach another website, the Referrer situation becomes more complicated.
Under IE, the value read through document.referrer of client Javascript is empty, but if you use traffic monitoring software to take a look, you will find that the Referer header in the HTTP request is actually Valuable, this may be a bug implemented by IE. At the same time, this value points to the address of the Flash file, not the address of the source web page.
After clicking Flash to reach a new window under Chrome 4.0, the Referrer also points to the address of the Flash file, not the address of the source web page.
Chrome 3.0 and Safari 3.2 are the same, both will lose the Referrer information.
Opera is the same as Firefox, the value of Referrer is the address of the source web page.
HTTPS to HTTP
When jumping from an HTTPS website to an HTTP website, the browser will not send a referrer. The behavior of all major browsers is the same.
For example, when we use Google Reader or Gmail under HTTPS and click a link to go to another website, then technically speaking, there is no difference between such access and the user directly typing in the URL.
The impact of the loss of Referrer on advertising traffic monitoring
If the Referrer is lost, Web Analytics will lose a very important part of the information, especially for advertising traffic, it will be impossible to know the actual source. At present, many domestic websites that use Google Adsense ads use the window.open method to open advertising links, so the Referrer will be lost under IE, and we know that IE is the browser with the largest market share at present, so its impact is huge. Big ones. Many traffic statistics tools will therefore classify this part of the traffic as "direct traffic", which is equivalent to the user directly typing in the URL.
For such a situation, advertisers need to add specific tracking parameters to the URL of the landing page when placing ads.
For example, if you click on a Flash ad, the URL it reaches is http://www.example.com/. In order to monitor which channel this traffic comes from, we can modify the landing URL of this ad to http. ://www.example.com/?src=sina, similar to this method, and then use Javascript code to extract this src parameter in the landing page, so that the advertising source information can be obtained.
When running Google Adwords, the background system has an "auto-tagging" option. When this option is enabled, Google will automatically add a gclid parameter when generating the landing page URL of all ads. This parameter can integrate data from the Google Analytics backend and the Adwords advertising backend. In this way, you can know which advertising campaign the advertising traffic corresponds to, which advertising source and advertising keywords and other information. The idea is actually similar to the one mentioned above. It’s just that Google automatically modified the URL for you.
Solution to the empty referer under IE
If you use the window.location.href method to jump under IE, the referer value will be empty. If you jump within the tag, the referer will not be empty. Therefore, this IE problem can be solved by using the following code
function gotoUrl(url){
if(window.VBArray){
var gotoLink = document.createElement('a');
gotoLink .href = url;
document.body.appendChild(gotoLink) ;
gotoLink .click(); ;
Prohibit browsers from using referer when accessing links
When we click on a link from a website to enter another page, the browser will add the Referer value to the header to identify this time The source page visited. However, this kind of identification may leak the user's privacy. Sometimes I don't want others to know where I clicked in. Is there any way to prevent the browser from sending a Referer?
•Use the new html5 solution, use rel="noreferrer", declare the connection attribute as noreferrer, currently only supported by chrome4.
•Use an intermediate page, but actually still send the referrer, such as using Google's connection redirection, noreferrer.js.
•Use javascript protocol link transfer, see the instructions below.
Open a new window, equivalent to target="_blank":
function open_window(link){
var arg = 'u003cscriptu003elocation.replace("' link '")u003c/scriptu003e';
window.open('javascript:window.name;', arg) ;
}
redirects to a connection, equivalent to target="_self":
function redirect(link){
var arg ='u003cscriptu003etop.location.replace("' link '")u003c/ scriptu003e';
var iframe = document.createElement('iframe');
iframe.src='javascript:window.name;';
iframe.name=arg;
document.body. appendChild(iframe);
}

JavaScript core data types are consistent in browsers and Node.js, but are handled differently from the extra types. 1) The global object is window in the browser and global in Node.js. 2) Node.js' unique Buffer object, used to process binary data. 3) There are also differences in performance and time processing, and the code needs to be adjusted according to the environment.

JavaScriptusestwotypesofcomments:single-line(//)andmulti-line(//).1)Use//forquicknotesorsingle-lineexplanations.2)Use//forlongerexplanationsorcommentingoutblocksofcode.Commentsshouldexplainthe'why',notthe'what',andbeplacedabovetherelevantcodeforclari

The main difference between Python and JavaScript is the type system and application scenarios. 1. Python uses dynamic types, suitable for scientific computing and data analysis. 2. JavaScript adopts weak types and is widely used in front-end and full-stack development. The two have their own advantages in asynchronous programming and performance optimization, and should be decided according to project requirements when choosing.

Whether to choose Python or JavaScript depends on the project type: 1) Choose Python for data science and automation tasks; 2) Choose JavaScript for front-end and full-stack development. Python is favored for its powerful library in data processing and automation, while JavaScript is indispensable for its advantages in web interaction and full-stack development.

Python and JavaScript each have their own advantages, and the choice depends on project needs and personal preferences. 1. Python is easy to learn, with concise syntax, suitable for data science and back-end development, but has a slow execution speed. 2. JavaScript is everywhere in front-end development and has strong asynchronous programming capabilities. Node.js makes it suitable for full-stack development, but the syntax may be complex and error-prone.

JavaScriptisnotbuiltonCorC ;it'saninterpretedlanguagethatrunsonenginesoftenwritteninC .1)JavaScriptwasdesignedasalightweight,interpretedlanguageforwebbrowsers.2)EnginesevolvedfromsimpleinterpreterstoJITcompilers,typicallyinC ,improvingperformance.

JavaScript can be used for front-end and back-end development. The front-end enhances the user experience through DOM operations, and the back-end handles server tasks through Node.js. 1. Front-end example: Change the content of the web page text. 2. Backend example: Create a Node.js server.

Choosing Python or JavaScript should be based on career development, learning curve and ecosystem: 1) Career development: Python is suitable for data science and back-end development, while JavaScript is suitable for front-end and full-stack development. 2) Learning curve: Python syntax is concise and suitable for beginners; JavaScript syntax is flexible. 3) Ecosystem: Python has rich scientific computing libraries, and JavaScript has a powerful front-end framework.


Hot AI Tools

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Undress AI Tool
Undress images for free

Clothoff.io
AI clothes remover

Video Face Swap
Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Hot Tools

Safe Exam Browser
Safe Exam Browser is a secure browser environment for taking online exams securely. This software turns any computer into a secure workstation. It controls access to any utility and prevents students from using unauthorized resources.

VSCode Windows 64-bit Download
A free and powerful IDE editor launched by Microsoft

MantisBT
Mantis is an easy-to-deploy web-based defect tracking tool designed to aid in product defect tracking. It requires PHP, MySQL and a web server. Check out our demo and hosting services.

SAP NetWeaver Server Adapter for Eclipse
Integrate Eclipse with SAP NetWeaver application server.

SecLists
SecLists is the ultimate security tester's companion. It is a collection of various types of lists that are frequently used during security assessments, all in one place. SecLists helps make security testing more efficient and productive by conveniently providing all the lists a security tester might need. List types include usernames, passwords, URLs, fuzzing payloads, sensitive data patterns, web shells, and more. The tester can simply pull this repository onto a new test machine and he will have access to every type of list he needs.
