Better support to add custom http header

better support to add custom http header, to us more flexible secure options like x-xss-protection or x-frame-option, etc. lots of security features require custom header