Django sites rely on Referrer headers for XSS protection