Mark Nottingham wrote:
> I'm not crazy about this approach, but it may be workable.
> ...
> Based on discussion so for, here's a straw-man:
> ...

Sounds good to me. Proposed patch: 

Note that I replaced "request header" by "header" in the second 
paragraph, and that I also added the Change to "A.2.  Changes from RFC 
2616" as:

    Allow Referer value of "about:blank" as alternative to not specifying
    it.  (Section 9.6)

BR, Julian

