Security Headers Test Page
This page has security headers set both via HTTP headers and meta tags.
Check the Network tab in Developer Tools to see the response headers.
Expected Headers:
- Permissions-Policy: accelerometer=(), camera=(), ...
- X-Frame-Options: SAMEORIGIN
- Strict-Transport-Security: max-age=31536000; includeSubDomains
- X-Content-Type-Options: nosniff