Response headers get lower cased once, upfront. Any consumer of a transfer's /
response's headers is now `mem.eql` rather than `ascii.eqlIgnoreCase`. This
fixes 1 or 2 WPT cases (e.g. XHR's `getAllResponseHeaders`), it also mergers
values in some cases (which is generally correct) - we need a follow up PR
to correctly merge in all cases.
Driven by a handful of /fetch/ WPT tests, three changes:
1 - Prevent libcurl from auto-inserting a 'application/x-www-form-urlencoded"
content type for types we really have no content-type for.
2 - Include origin header in all requests that should have it. This is something
CorsGate was doing in most cases, but cors can be disabled, so the logic
is now moved to HttpClient.
3 - Expands on the header guard added in https://github.com/lightpanda-io/browser/pull/3374/
Adds more modes and more header check. Request.init also uses the header
guard now