<p>Using Django? Be careful with custom values for <code><meta name="referrer"></code>! Yes, a HTML tag can break Django CSRF protection: (PS: note old browsers might misbehave with new <code><meta name="referrer"></code> values too! Better avoid it.)</p>