Hello Cesar,
Are you talking about security header like these? I usually confgure this type of security headers at Web server/Proxy level.
- Strict-Transport-Security
- Content-Security-Policy
- X-XSS-Protection
- X-Frame-Options "SAMEORIGIN";
- X-Content-Type-Options nosniff;
- Referrer-Policy "strict-origin";
- Permissions-Policy
Regards,
------------------------------
Gabriel Aberasturi
Versia tecnologias emergentes
------------------------------