P3P | CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p" |
Strict-Transport-Security | max-age=15552000; preload |
Cache-Control | private, no-cache, no-store, must-revalidate |
Expires | Sat, 01 Jan 2000 00:00:00 GMT |
content-security-policy | default-src * data: blob:;script-src *.facebook.com *.fbcdn.net *.facebook.net *.google-analytics.com *.virtualearth.net *.google.com 127.0.0.1:* *.spotilocal.com:* 'unsafe-inline' 'unsafe-eval' fbstatic-a.akamaihd.net fbcdn-static-b-a.akamaihd.net *.atlassolutions.com blob: data:;style-src * 'unsafe-inline' data:;connect-src *.facebook.com *.fbcdn.net *.facebook.net *.spotilocal.com:* *.akamaihd.net wss://*.facebook.com:* https://fb.scanandcleanlocal.com:* *.atlassolutions.com attachment.fbsbx.com ws://localhost:* blob: chrome-extension://boadgeojelhgndaghljhdicfkmllpafd; |
Access-Control-Allow-Credentials | true |
X-Frame-Options | DENY |
Pragma | no-cache |
Access-Control-Allow-Origin | https://www.facebook.com |
Access-Control-Expose-Headers | X-FB-Debug, X-Loader-Length |
public-key-pins-report-only | max-age=500; pin-sha256="WoiWRyIOVNa9ihaBciRSC7XHjliYS9VwUGOIud4PB18="; pin-sha256="r/mIkG3eEpVdm+u/ko/cwxzOMo1bk4TyHIlByibiA5E="; pin-sha256="q4PO2G2cbkZhZ82+JgmRUyGMoAeozA+BSXVXQWB8XWQ="; report-uri="http://reports.fb.com/hpkp/" |
access-control-allow-method | OPTIONS |
X-XSS-Protection | 0 |
X-Content-Type-Options | nosniff |
Vary | Origin, Accept-Encoding |
Content-Encoding | gzip |
Content-Type | text/html |
X-FB-Debug | bxkdwvXtvUYkskMqWVTIqBAqfgwGKR5X2MqzzDUIq5eBPpHVYRcNtFS7zikHQhXX42SqlI7Xf17qvCAGHDtmow== |
Transfer-Encoding | chunked |
Connection | keep-alive |