1️⃣ site-one (referrer sandbox)

Browser's default referrer policy

Detected default policy in this browser:
...

chrome logo Are you in Chrome? If so: you can experiment with another default policy. Enable the flag at chrome://flags/#reduced-referrer-granularity.

Pick a referrer policy

Let's fetch stuff

Request from
https://site-one.glitch.me/stuff/detail?tag=blue

to...
What was sent in the Referer header?
https://site-one.glitch.me/other
= same-origin
...
https://site-two.glitch.me/
= cross-origin no downgrade
...
http://site-two.glitch.me/
=
cross-origin with downgrade
[BLOCKED because mixed content]

Let's embed a cross-origin HTTPS iframe

iframe src = "https://site-two.glitch.me/ifr"