Implement Origin-Signed HTTP Responses (for WebPackage Loading)
Assumption: An origin-signed HTTP exchange is served in a CBOR envelope.
Expected behavior: Chrome's loading pipeline fetches the envelope, parses CBOR, extracts the signed HTTP headers, verifies the headers using the signature in the header, and also verifies the integrity of the message body with MI headers.
Spec (I-D): https://wicg.github.io/webpackage/draft-yasskin-http-origin-signed-responses.html
(W3C spec for loading is expected to be published too)