Skip to content

Query String Filter

yan edited this page Sep 21, 2023 · 20 revisions

The Brave query string filter aims at preventing the tracking of individual users without interfering with coarse-grained campaign-level tracking. We target parameters which are known to be specific to:

  • a user,
  • an email address, or
  • an individual click.

This kind of tracking is typically used to sync cookie, that is the practice of synchronizing the value of first-party cookies on different domains, to link clicks inside an email message to a website visit, or to leak a user's identity across site boundaries.

In addition, we may remove parameters that can be used to circumvent our referrer trimming protections, that is parameters that would leak more than just the referring page's origin (e.g. including the referring page's path).

Implementation

The way that the filter works is that we remove from the query string any parameters (i.e. the parameter name and its value) before we proceed with a non-same-site GET request (navigations, subresources and redirects). This means that such parameters never make it to the server, URL bar or the Referer header, and cannot be recovered by scripts running on a page.

A notable exception to this intervention is the unsubscribe link in emails. If a user-identifying tracking parameter is required for that functionality to work, we make an exception. For example, the mkt_tok parameter is removed except when the string unsubscribe is present in the URL.

All issues related to this feature are tagged with the privacy/query-filter label.

List

The current list of parameters we filter can be seen in brave/browser/net/brave_query_filter.cc:: kSimpleQueryStringTrackers.

QA

There is a test page at https://fmarier.github.io/brave-testing/query-filter.html.

Clone this wiki locally