Onion listener trust boundary
With ONION_LOCATION set, the app decides per request whether it came through
the onion (Tor) listener. That decides Secure cookies, HSTS and the
Onion-Location header. The client-supplied Host header never
decides it: a request on the HTTPS listener could claim
Host: <anything>.onion. Instead, nginx sets X-OW-Onion: 1 only in the
onion server block and clears it in the regular one, like the IP headers of layer 1. Both
hold only while the app port is reachable through this nginx alone
(Offering an onion address).