# \[Solved\] 14.0.3-\>14.0.4 & "Referrer-Policy" HTTP header Warning appears Again

**URL:** <https://help.nextcloud.com/t/solved-14-0-3-14-0-4-referrer-policy-http-header-warning-appears-again/41781>\
**Category:** ℹ️ Support\
**Tags:** nc14\
**Created:** [November 23, 2018, 6:27am UTC](https://help.nextcloud.com/t/solved-14-0-3-14-0-4-referrer-policy-http-header-warning-appears-again/41781 "2018-11-23T06:27:56Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![vvong](https://help.nextcloud.com/letter_avatar/vvong/32/5_5575768a8748004e209b776fc1b2916d.png) [@vvong](https://help.nextcloud.com/u/vvong)\
**Post date:** [November 23, 2018, 6:27am UTC](https://help.nextcloud.com/t/solved-14-0-3-14-0-4-referrer-policy-http-header-warning-appears-again/41781/1 "2018-11-23T06:27:56Z")

</div>

Edit: I just comment out those lines in .htaccess and the warning vanishes.

i.e. It will be ideal if the upgrade process check (if possible) that users have already added this referrer-policy header to their conf before add it by default to .htaccess

Thanks

-------------- Original message ------------------

Everything works fine when I was with 14.0.3

Right after upgrade to 14.0.4 an hour ago, it emerges again.

Last time, I added to apache’s website.conf the following lines to fix the issue, and it is still there.

```auto
\<IfModule mod_headers.c>
  Header always set Strict-Transport-Security "max-age=15552000; includeSubDomains"
  Header always set Referrer-Policy "no-referrer"
\</IfModule>

```

This time, I also checked .htaccess and see the following lines there by default

```auto
  <IfModule mod_env.c>
    # Add security and privacy related headers
    Header set X-Content-Type-Options "nosniff"
    Header set X-XSS-Protection "1; mode=block"
    Header set X-Robots-Tag "none"
    Header set X-Download-Options "noopen"
    Header set X-Permitted-Cross-Domain-Policies "none"
    Header set Referrer-Policy "no-referrer"
    SetEnv modHeadersAvailable true
  </IfModule>

```

I run

```auto
$ sudo apachectl -M

```

and it indicates that env\_module is loaded.

Any idea what is wrong?

Thanks

---

<div class="post-metadata">

**Author:** ![ldc-kah](https://help.nextcloud.com/letter_avatar/ldc-kah/32/5_5575768a8748004e209b776fc1b2916d.png) [@ldc-kah](https://help.nextcloud.com/u/ldc-kah)\
**Post date:** [November 26, 2018, 7:42am UTC](https://help.nextcloud.com/t/solved-14-0-3-14-0-4-referrer-policy-http-header-warning-appears-again/41781/2 "2018-11-26T07:42:27Z")

</div>

I also had this issue. I had

```
Header always set Referrer-Policy "no-referrer"

```

in /etc/apache2/conf-available/security.conf. Replacing with

```
Header set Referrer-Policy "no-referrer"

```

and restarting Apache and the warning goes away. Now what does the “always” option do?

---

<div class="post-metadata">

**Author:** ![FeistyViking](https://help.nextcloud.com/user_avatar/help.nextcloud.com/feistyviking/32/15447_2.png) [@FeistyViking](https://help.nextcloud.com/u/FeistyViking)\
**Post date:** [November 26, 2018, 5:35pm UTC](https://help.nextcloud.com/t/solved-14-0-3-14-0-4-referrer-policy-http-header-warning-appears-again/41781/3 "2018-11-26T17:35:58Z")

</div>

Exact issue here as well.

I did the same thing as you and just commented out the lines.

+1 on adding that check to the update process (if possible)

Thanks for the good tip!

---

<div class="post-metadata">

**Author:** ![wwe](https://help.nextcloud.com/user_avatar/help.nextcloud.com/wwe/32/72963_2.png) [@wwe](https://help.nextcloud.com/u/wwe)\
**Post date:** [December 4, 2024, 8:17am UTC](https://help.nextcloud.com/t/solved-14-0-3-14-0-4-referrer-policy-http-header-warning-appears-again/41781/4 "2024-12-04T08:17:52Z")

</div>



---

<div class="post-metadata">

**Author:** ![wwe](https://help.nextcloud.com/user_avatar/help.nextcloud.com/wwe/32/72963_2.png) [@wwe](https://help.nextcloud.com/u/wwe)\
**Post date:** [December 9, 2024, 3:38pm UTC](https://help.nextcloud.com/t/solved-14-0-3-14-0-4-referrer-policy-http-header-warning-appears-again/41781/5 "2024-12-09T15:38:29Z")

</div>


