Enable blocking of subresource requests whose URLs include credentials.

This patch flips the 'BlockCredentialedSubresources' flag to 'stable', and
ties it to a feature flag in //content that we can use as a kill switch if
it turns out that enterprise usage of the feature is higher than we hope
(the overall numbers still look reasonably low[1]).

Intent: https://groups.google.com/a/chromium.org/forum/#!topic/blink-dev/lx-U_JR2BF0

[1]: https://www.chromestatus.com/metrics/feature/timeline/popularity/532

BUG=504300,435547

Review-Url: https://codereview.chromium.org/2779603002
Cr-Commit-Position: refs/heads/master@{#459781}
10 files changed