Add "X-Content-Type-Options" and "Strict-Transport-Security"

OWASP recommend to set these HTTP response headers.

  • X-Content-Type-Options

  • Strict-Transport-Security