return 301 https://$host$request_uri;
add_header Strict-Transport-Security 'max-age=31536000; includeSubDomains' always;
https:// scheme./login without the scheme, causing a protocol downgrade.
csrftoken=value; Secure; HttpOnly; SameSite=Lax
server_tokens off; to nginx.conf to stop leaking nginx/1.20.1.
add_header X-XSS-Protection "1; mode=block" always; in nginx or Cloudflare Transform Rules.