headers->set('X-XSS-Protection', '1'); return $response; } }