Move HTTP-Bad to Feature API and implement new options

This CL moves the HTTP-Bad from outdated field trial groups to the Feature API
with parameters to control the UI treatment. It adds three new UI treatments for
nonsecure  pages:

- mark all nonsecure pages as Not Secure
- mark all nonsecure pages as Not Secure and treat them as actively dangerous when
  a form field is edited
- mark all nonsecure pages as Not Secure and treat them as actively dangerous for
  passwords and credit card fields

This doesn't implement any DevTools or Page Info changes for these configurations.

Bug: 797437,740395
Cq-Include-Trybots: master.tryserver.chromium.mac:ios-simulator-cronet;master.tryserver.chromium.mac:ios-simulator-full-configs
Change-Id: I646502a05967b63d3c34015d0d597ce5382248f9
Reviewed-on: https://chromium-review.googlesource.com/843456
Reviewed-by: Eugene But <[email protected]>
Reviewed-by: Jesse Doherty <[email protected]>
Reviewed-by: Eric Lawrence <[email protected]>
Commit-Queue: Emily Stark <[email protected]>
Cr-Commit-Position: refs/heads/master@{#526857}
19 files changed