Secure headers
Response headers can reduce browser-side exposure.
What it is
Response headers can reduce browser-side exposure.
When to use it
Add a policy suited to actual resources and HTTPS deployment.
Syntax
X-Content-Type-Options: nosniff
Referrer-Policy: same-origin
Content-Security-Policy: default-src 'self'; frame-ancestors 'none'Example
$response = $next($request);
$response->headers->set("X-Content-Type-Options", "nosniff");
$response->headers->set("Referrer-Policy", "same-origin");
return $response;Common mistakes
CSP must account for inline scripts with nonce/hash; HSTS applies only to HTTPS; headers cannot replace encoding.