Content-Type | text/html; charset=utf-8 |
Cache-Control | no-cache |
X-Frame-Options | DENY |
Strict-Transport-Security | max-age=2592000; includeSubdomains |
X-XSS-Protection | 1; mode=block |
X-Content-Type-Options | nosniff |
Content-Security-Policy | script-src 'self' 'unsafe-eval' 'unsafe-inline' *.google.com *.google-analytics.com ajax.googleapis.com *.firebaseio.com www.gstatic.com *.youtube.com *.ytimg.com ; child-src 'self' https://www.google.com https://www.youtube.com; object-src 'none'; frame-src 'self' https://www.google.com https://www.youtube.com *.firebaseapp.com *.doubleclick.net; report-uri /csp |
Content-Encoding | gzip |
X-Cloud-Trace-Context | 5adb2f798e7f0de557385735da6b528d |
Vary | Accept-Encoding |
Server | Google Frontend |
Alt-Svc | hq=":443"; ma=2592000; quic=51303431; quic=51303339; quic=51303338; quic=51303337; quic=51303335,quic=":443"; ma=2592000; v="41,39,38,37,35" |
Transfer-Encoding | chunked |