Some x-wmf-* headers should be included in the response so it can be captured by haproxy for analytics purposes.
For now, the following headers should be returned:
- x-wmf-ratelimit-class
x-wmf-user-id(postponed due to privacy concerns; MW to expose auth type instead, see T418606)
NOTE: These headers should NOT be exposed to the client, so haproxy should filter them out (T417781)