XEP-0363: clients SHOULD NOT interpret headers

2022-01-04
@ -343,6 +343,7 @@ Access-Control-Allow-Methods: OPTIONS, HEAD, GET, PUT
Access-Control-Allow-Headers: Authorization, Content-Type
Access-Control-Allow-Credentials: true
<p>Clients SHOULD NOT interpret headers and treat them as opaque.</p>
<section1 topic='Security Considerations' anchor='security'>
<section2 topic="Server side" anchor="server">