The API gateway should add security headers to API responses, based on some simple rules.
For reference, see the security header filter implemented in RESTbase: https://phabricator.wikimedia.org/diffusion/GRES/browse/master/lib/security_response_header_filter.js
See PCS related task: T321194: Implement Security Response Header Filter logic outside RESTBase for PCS