app: add security headers middleware
X-Frame-Options: DENY and frame-ancestors 'none' stop clickjacking of OIDC, register-confirm, and debug HTML pages. nosniff and no-referrer are cheap defence-in-depth for the same surfaces. Updates #3157
K
Kristoffer Dalby committed
0567cb6da3a294110bbd27f9b51c48e05938d57b
Parent: 5a7cafd