more_set_headers "X-XSS-Protection: 0"; more_set_headers "X-Frame-Options: SAMEORIGIN"; more_set_headers "X-Content-Type-Options: nosniff"; more_set_headers "Referrer-Policy: strict-origin-when-cross-origin"; more_set_headers "Content-Security-Policy: $content_security_policy"; more_set_headers "Strict-Transport-Security: $hsts_header";