some new non-standard headers for prevent (not always :O) xss, csrf, clickjacking.
http://en.wikipedia.org/wiki/List_of_HTTP_header_fields#Common_non-standard_response_headers
↧