Forum OpenACS Q&A: Re: RFC: Security policy for OpenACS (Security hole in OpenACS 5.1!)

I don't think the referer is easily forged in this case since it comes from the browser of the admin. Hopefully this cannot be javascripted or changed in some other way.