remove unnecessary internal middleware header from response (#73482)
x-middleware-set-cookie is an internal header used by the middleware
handler and doesn't need to be forwarded onto the response.
this also adds handling to filter out internal request headers as they
aren't intended to be used externally.
---------
Co-authored-by: JJ Kasper <jj@jjsweb.site>