This reminds me of some vague memories of a time long ago where some websites had a secure login page that asks for a username&pw but every other page after just checked the referall header. It wasn't a very secure system and people shared the header values needed to bypass logging in.
That's basically a degenerate form of capability-based security. Sharing the referrer header is delegating access rights. Of course, that's not actually a property you want in this case.