Skip to content

Conversation

@APraxx
Copy link

@APraxx APraxx commented Jun 11, 2023

Minimize the X-Requested-With (XRW) header for privacy

Until Google offers other means, like their Blog suggests, this seems like a sensible solution.

Reference: https://android-developers.googleblog.com/2023/02/improving-user-privacy-by-requiring-opt-in-to-send-x-requested-wih-header-from-webview.html

Minimized the X-Requested-With (XRW) header for privacy
@APraxx APraxx changed the title Minimze XRW in the WebViewActivity Minimize XRW in the WebViewActivity Jun 11, 2023
@cylonid
Copy link
Owner

cylonid commented Aug 12, 2024

Hi,
thanks for bringing this to my attention. The header in question is not set from WebView v114 onwards, so this should not be necessary any more.

@APraxx
Copy link
Author

APraxx commented Aug 12, 2024

Hi,

Thanks i read that too but couldn't see it in practice.
Maybe i need to recompile because i still see it.
Was leaky hack anyway because it won't work on images and resources.

Other thing i noticed is original user agent is available through SEC-CH-UA, but i don't know if that's not a browser thing.

@APraxx
Copy link
Author

APraxx commented Oct 28, 2024

#141 refers to the mentioned SEC-CH-UA

@APraxx APraxx closed this Oct 28, 2024
@APraxx APraxx deleted the feature-min-xrw branch October 28, 2024 19:10
@APraxx APraxx restored the feature-min-xrw branch October 28, 2024 21:01
@APraxx
Copy link
Author

APraxx commented Oct 28, 2024

Tested on my current setup X-Requested-With still there

Reproduce:
open: duckduckgo.com
search for: user agent
in the last line it shows on my phone

@APraxx APraxx reopened this Oct 28, 2024
@APraxx APraxx marked this pull request as draft October 28, 2024 21:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants