'Referrer-Policy' を 'same-origin' に設定

Very nasty hack here but

you could resolve this in nginx by adding a proxy_hide_header and follow it with your own add_header