+ This page has a server middleware that sets CSP and Referrer-Policy to some example values
+ But it also has a security option that suppresses these headers
+
+ All security options on this page are generated at runtime
+ The buggy CSP value with a fixed time value should be present in the headers
+ Also, the X-Powered-By header should be apparent with the Nuxt value
+