* Add security headers with sensible default values. * Add test to check that default security headers are added to http responses * Also test the static handler.