Control Referrer Data with Referrer-Policy
A browser can attach source-page information to an outbound request through the HTTP Referer header. That context can help with analytics, navigation flows, and abuse detection, but it can also expose more URL data than a destination needs. An explicit Referrer-Policy gives a site control over this boundary. The main security objective is simple: send the minimum source context needed for legitimate behavior, especially when a request crosses to another origin.