HTTP traces currently include `Cookie` headers but exclude `Authorization` headers by default. We should consider excluding `Cookie` headers by default.