The HttpSecurity#headers() Javadoc did not accurately reflect changes made to the HeadersConfigurer in Spring Security 4.x.