Referrer-Policy is unsafe
Referrer-Policy is an unsafe value that can send the full URL on cross-origin requests.
Why it matters
The path and query string can leak tokens or internal routes to other sites.
What to do
Use strict-origin-when-cross-origin, strict-origin, same-origin, or no-referrer.
Reference
A strict Referrer-Policy limits how much of the URL is sent to other origins.