To do that, websites really should make use of the origin-when-cross-origin plan. This will permit supporting browsers to send just the origin because the Referer header. This confined referral details applies even when both equally web sites use HTTPS. Since your web site contains a protected SSL/TLS certification, a hacker https://keithr901tmd2.mycoolwiki.com/user