  1. add_header X-XSS-Protection "1; mode=block";
  2. add_header Content-Security-Policy "<policy>";
  3. add_header Strict-Transport-Security "max-age=31536000; includeSubdomains;";
  4. add_header Public-Key-Pins 'pin-sha256="<primary>"; pin-sha256="<backup>"; max-age=5184000; includeSubDomains';
  5. add_header X-Content-Type-Options nosniff;
  6. add_header Referrer-Policy "no-referrer";
