Unfortunately I've had to leave the check disabed as Brakeman can't see inside the safe_referer method so doesn't realise that it is cleaning the referer.
Followup to #2269