HTTP Direct GET request to file vs GET from html tagWhat's the difference between a POST and a PUT HTTP REQUEST?HTTP GET request in JavaScript?Is an entity body allowed for an HTTP DELETE request?Where should I put <script> tags in HTML markup?HTTP GET with request bodymaximum length of HTTP GET request?How to use java.net.URLConnection to fire and handle HTTP requestsRedirect from an HTML pageHow is an HTTP POST request made in node.js?How are parameters sent in an HTTP POST request?

Did Shadowfax go to Valinor?

How is it possible to have an ability score that is less than 3?

How much of data wrangling is a data scientist's job?

How to take photos in burst mode, without vibration?

In Romance of the Three Kingdoms why do people still use bamboo sticks when papers are already invented?

Why doesn't H₄O²⁺ exist?

What to put in ESTA if staying in US for a few days before going on to Canada

What is going on with Captain Marvel's blood colour?

How can I make my BBEG immortal short of making them a Lich or Vampire?

Do I have a twin with permutated remainders?

Does a druid starting with a bow start with no arrows?

What do you call someone who asks many questions?

I'm flying to France today and my passport expires in less than 2 months

Emailing HOD to enhance faculty application

Why does Arabsat 6A need a Falcon Heavy to launch

Stopping power of mountain vs road bike

I would say: "You are another teacher", but she is a woman and I am a man

Alternative to sending password over mail?

Why does Kotter return in Welcome Back Kotter

Would Slavery Reparations be considered Bills of Attainder and hence Illegal?

Is it possible to run Internet Explorer on OS X El Capitan?

Facing a paradox: Earnshaw's theorem in one dimension

What reasons are there for a Capitalist to oppose a 100% inheritance tax?

Were any external disk drives stacked vertically?



HTTP Direct GET request to file vs GET from html tag


What's the difference between a POST and a PUT HTTP REQUEST?HTTP GET request in JavaScript?Is an entity body allowed for an HTTP DELETE request?Where should I put <script> tags in HTML markup?HTTP GET with request bodymaximum length of HTTP GET request?How to use java.net.URLConnection to fire and handle HTTP requestsRedirect from an HTML pageHow is an HTTP POST request made in node.js?How are parameters sent in an HTTP POST request?






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








0















Is there an accurate way to distinguish between a GET request directly to a file :



website.com/file.css



and a GET request to the same file but when loading a page that includes:



<style rel = "file.css">


As far as I can tell, the HTTP requests are pretty much identical.



Are there any solutions which don't involve:



Monitoring the server request logs (timing / sequence based).



Adding in GET parameters, e.g. file.css?r=dgsfgfgd



Using CSP reporting.










share|improve this question






















  • You can check the "Origin" or "Referrer" header from the HTTP request, if either of the header is empty it's manually requested via the browser. However, one can manually craft a request to get around this.

    – Dominick Navarro
    Mar 9 at 1:23











  • Thanks for your response, I'm not too worried about people creating their own requests, more so about people opening source files directly. In regards to origin / referrer: Using Google Chrome, neither are set when I view the file in the above situations. The Referrer Policy is set, and is slightly different, one no-referrer and the other no-referrer-when-downgrade, but I'm not sure if that's a reliable way to distinguish the two. Everything else in the request is pretty much identical.

    – Danbardo
    Mar 9 at 1:57


















0















Is there an accurate way to distinguish between a GET request directly to a file :



website.com/file.css



and a GET request to the same file but when loading a page that includes:



<style rel = "file.css">


As far as I can tell, the HTTP requests are pretty much identical.



Are there any solutions which don't involve:



Monitoring the server request logs (timing / sequence based).



Adding in GET parameters, e.g. file.css?r=dgsfgfgd



Using CSP reporting.










share|improve this question






















  • You can check the "Origin" or "Referrer" header from the HTTP request, if either of the header is empty it's manually requested via the browser. However, one can manually craft a request to get around this.

    – Dominick Navarro
    Mar 9 at 1:23











  • Thanks for your response, I'm not too worried about people creating their own requests, more so about people opening source files directly. In regards to origin / referrer: Using Google Chrome, neither are set when I view the file in the above situations. The Referrer Policy is set, and is slightly different, one no-referrer and the other no-referrer-when-downgrade, but I'm not sure if that's a reliable way to distinguish the two. Everything else in the request is pretty much identical.

    – Danbardo
    Mar 9 at 1:57














0












0








0








Is there an accurate way to distinguish between a GET request directly to a file :



website.com/file.css



and a GET request to the same file but when loading a page that includes:



<style rel = "file.css">


As far as I can tell, the HTTP requests are pretty much identical.



Are there any solutions which don't involve:



Monitoring the server request logs (timing / sequence based).



Adding in GET parameters, e.g. file.css?r=dgsfgfgd



Using CSP reporting.










share|improve this question














Is there an accurate way to distinguish between a GET request directly to a file :



website.com/file.css



and a GET request to the same file but when loading a page that includes:



<style rel = "file.css">


As far as I can tell, the HTTP requests are pretty much identical.



Are there any solutions which don't involve:



Monitoring the server request logs (timing / sequence based).



Adding in GET parameters, e.g. file.css?r=dgsfgfgd



Using CSP reporting.







html apache http server






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked Mar 8 at 23:40









DanbardoDanbardo

267




267












  • You can check the "Origin" or "Referrer" header from the HTTP request, if either of the header is empty it's manually requested via the browser. However, one can manually craft a request to get around this.

    – Dominick Navarro
    Mar 9 at 1:23











  • Thanks for your response, I'm not too worried about people creating their own requests, more so about people opening source files directly. In regards to origin / referrer: Using Google Chrome, neither are set when I view the file in the above situations. The Referrer Policy is set, and is slightly different, one no-referrer and the other no-referrer-when-downgrade, but I'm not sure if that's a reliable way to distinguish the two. Everything else in the request is pretty much identical.

    – Danbardo
    Mar 9 at 1:57


















  • You can check the "Origin" or "Referrer" header from the HTTP request, if either of the header is empty it's manually requested via the browser. However, one can manually craft a request to get around this.

    – Dominick Navarro
    Mar 9 at 1:23











  • Thanks for your response, I'm not too worried about people creating their own requests, more so about people opening source files directly. In regards to origin / referrer: Using Google Chrome, neither are set when I view the file in the above situations. The Referrer Policy is set, and is slightly different, one no-referrer and the other no-referrer-when-downgrade, but I'm not sure if that's a reliable way to distinguish the two. Everything else in the request is pretty much identical.

    – Danbardo
    Mar 9 at 1:57

















You can check the "Origin" or "Referrer" header from the HTTP request, if either of the header is empty it's manually requested via the browser. However, one can manually craft a request to get around this.

– Dominick Navarro
Mar 9 at 1:23





You can check the "Origin" or "Referrer" header from the HTTP request, if either of the header is empty it's manually requested via the browser. However, one can manually craft a request to get around this.

– Dominick Navarro
Mar 9 at 1:23













Thanks for your response, I'm not too worried about people creating their own requests, more so about people opening source files directly. In regards to origin / referrer: Using Google Chrome, neither are set when I view the file in the above situations. The Referrer Policy is set, and is slightly different, one no-referrer and the other no-referrer-when-downgrade, but I'm not sure if that's a reliable way to distinguish the two. Everything else in the request is pretty much identical.

– Danbardo
Mar 9 at 1:57






Thanks for your response, I'm not too worried about people creating their own requests, more so about people opening source files directly. In regards to origin / referrer: Using Google Chrome, neither are set when I view the file in the above situations. The Referrer Policy is set, and is slightly different, one no-referrer and the other no-referrer-when-downgrade, but I'm not sure if that's a reliable way to distinguish the two. Everything else in the request is pretty much identical.

– Danbardo
Mar 9 at 1:57













0






active

oldest

votes












Your Answer






StackExchange.ifUsing("editor", function ()
StackExchange.using("externalEditor", function ()
StackExchange.using("snippets", function ()
StackExchange.snippets.init();
);
);
, "code-snippets");

StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "1"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);

else
createEditor();

);

function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);



);













draft saved

draft discarded


















StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55072499%2fhttp-direct-get-request-to-file-vs-get-from-html-tag%23new-answer', 'question_page');

);

Post as a guest















Required, but never shown

























0






active

oldest

votes








0






active

oldest

votes









active

oldest

votes






active

oldest

votes















draft saved

draft discarded
















































Thanks for contributing an answer to Stack Overflow!


  • Please be sure to answer the question. Provide details and share your research!

But avoid


  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.

To learn more, see our tips on writing great answers.




draft saved


draft discarded














StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55072499%2fhttp-direct-get-request-to-file-vs-get-from-html-tag%23new-answer', 'question_page');

);

Post as a guest















Required, but never shown





















































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown

































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown







Popular posts from this blog

Identity Server 4 is not redirecting to Angular app after login2019 Community Moderator ElectionIdentity Server 4 and dockerIdentityserver implicit flow unauthorized_clientIdentityServer Hybrid Flow - Access Token is null after user successful loginIdentity Server to MVC client : Page Redirect After loginLogin with Steam OpenId(oidc-client-js)Identity Server 4+.NET Core 2.0 + IdentityIdentityServer4 post-login redirect not working in Edge browserCall to IdentityServer4 generates System.NullReferenceException: Object reference not set to an instance of an objectIdentityServer4 without HTTPS not workingHow to get Authorization code from identity server without login form

2005 Ahvaz unrest Contents Background Causes Casualties Aftermath See also References Navigation menue"At Least 10 Are Killed by Bombs in Iran""Iran"Archived"Arab-Iranians in Iran to make April 15 'Day of Fury'"State of Mind, State of Order: Reactions to Ethnic Unrest in the Islamic Republic of Iran.10.1111/j.1754-9469.2008.00028.x"Iran hangs Arab separatists"Iran Overview from ArchivedConstitution of the Islamic Republic of Iran"Tehran puzzled by forged 'riots' letter""Iran and its minorities: Down in the second class""Iran: Handling Of Ahvaz Unrest Could End With Televised Confessions""Bombings Rock Iran Ahead of Election""Five die in Iran ethnic clashes""Iran: Need for restraint as anniversary of unrest in Khuzestan approaches"Archived"Iranian Sunni protesters killed in clashes with security forces"Archived

Can't initialize raids on a new ASUS Prime B360M-A motherboard2019 Community Moderator ElectionSimilar to RAID config yet more like mirroring solution?Can't get motherboard serial numberWhy does the BIOS entry point start with a WBINVD instruction?UEFI performance Asus Maximus V Extreme