# humble (HTTP Headers Analyzer)
# https://github.com/rfc-st/humble/
#
# MIT License
#
# Copyright (c) 2020-2023 Rafa 'Bluesman' Faura (rafael.fcucalon@gmail.com)
#
# Permission is hereby granted, free of charge, to any person obtaining a copy
# of this software and associated documentation files (the "Software"), to deal
# in the Software without restriction, including without limitation the rights
# to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
# copies of the Software, and to permit persons to whom the Software is
# furnished to do so, subject to the following conditions:
#
# The above copyright notice and this permission notice shall be included in
# all copies or substantial portions of the Software.
#
# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
# IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
# FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
# AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
# LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
# OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
# SOFTWARE.

Accept-CH: Deprecated Value
Accept-CH: Ignored Header via Unsafe Scheme
Accept-CH-Lifetime: Deprecated Header
Access-Control-Allow-Credentials: Incorrect Values
Access-Control-Allow-Methods: Insecure Methods
Access-Control-Allow-Origin: Unsafe Values
Access-Control-Max-Age: Excessive Value
Allow: Insecure Methods
Cache-Control: No Valid Directives
Cache-Control: Recommended Values
Clear-Site-Data: Ignored Header via Unsafe Scheme
Clear-Site-Data: No Valid Directives
Content-DPR: Deprecated Header
Content-Encoding: No Valid Directives
Content-Security-Policy: Deprecated Directives
Content-Security-Policy: Incorrect Values
Content-Security-Policy: Insecure Schemes
Content-Security-Policy: IP detected
Content-Security-Policy: No Valid Directives
Content-Security-Policy: Too Permissive Sources
Content-Security-Policy: Unsafe Funcionality
Content-Security-Policy: Unsafe Nonce
Content-Security-Policy: Unsafe Values
Content-Security-Policy-Report-Only: Deprecated Directives
Content-Type: Deprecated Values
Content-Type: Non-HTML MIME type
Critical-CH: Ignored Header via Unsafe Scheme
Cross-Origin-Embedder-Policy: No Valid Directives
Cross-Origin-Opener-Policy: No Valid Directives
Cross-Origin-Resource-Policy: No Valid Directives
Digest: Deprecated Header
Etag: Potentially Unsafe Header
Expect-CT: Deprecated Header
Expires: Ignored Header
Feature-Policy: Deprecated Header
HTTP: Domain Via Unsafe Scheme
Keep-Alive: Ignored Header
Large-Allocation: Deprecated Header
Onion-Location: Potentially Unsafe Header
Origin-Agent-Cluster: No Valid Directives
P3P: Deprecated Header
Permissions-Policy: Deprecated Values
Permissions-Policy: Incorrect Values
Permissions-Policy: No Valid Features
Permissions-Policy: Too Permissive Value
Pragma: Deprecated Header
Proxy-Authenticate: Unsafe Value
Public-Key-Pins: Deprecated Header
Public-Key-Pins-Report-Only: Deprecated Header
Referrer-Policy: Incorrect Value
Referrer-Policy: Recommended Values
Referrer-Policy: Unsafe Value
Server-Timing: Potentially Unsafe Header
Set-Cookie: Cookie Prefixes
Set-Cookie: Insecure Attributes
Set-Cookie: Insecure Schemes
Set-Cookie: Missing Attribute
SourceMap: Unsafe Funcionality
Strict-Dynamic: Incorrect Header
Strict-Transport-Security: Duplicated Values
Strict-Transport-Security: Ignored Header via Unsafe Scheme
Strict-Transport-Security: Recommended Values
Supports-Loading-Mode: No Valid Directives
Surrogate-Control: No Valid Directives
Timing-Allow-Origin: Potentially Unsafe Header
Tk: Deprecated Header
Trailer: Disallowed Directives
Transfer-Encoding: No Valid Directives
Warning: Deprecated Header
WWW-Authenticate: Unsafe Value
X-Content-Security-Policy: Deprecated Header
X-Content-Security-Policy-Report-Only: Deprecated Header
X-Content-Type-Options: Duplicated Values
X-Content-Type-Options: Incorrect Value
X-DNS-Prefetch-Control: Potentially Unsafe Header
X-Download-Options: Deprecated Header
X-Frame-Options: Deprecated Values
X-Frame-Options: Duplicated Values
X-Frame-Options: Incorrect Values
X-Pad: Deprecated Header
X-Permitted-Cross-Domain-Policies: Unsafe Value
X-Pingback: Unsafe Value
X-Robots-Tag: Unsafe Value
X-Robots-Tag: No Valid Directives
X-Runtime: Unsafe Value
X-SourceMap: Deprecated Header
X-UA-Compatible: Deprecated Header
X-Webkit-CSP: Deprecated Header
X-Webkit-CSP-Report-Only: Deprecated Header
X-XSS-Protection: Deprecated Header
X-XSS-Protection: Duplicated Values
X-XSS-Protection: Unsafe Value