Set 'Referrer-Policy' => 'same-origin'

Very nasty hack here but

you could resolve this in nginx by adding a proxy_hide_header and follow it with your own add_header