40c91cec55
Set X-Content-Type-Options: nosniff (so served file bytes are not MIME sniffed), X-Frame-Options: DENY, and Referrer-Policy: no-referrer on all responses via middleware. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>