Server | nginx |
Content-Type | text/html; charset=UTF-8 |
Transfer-Encoding | chunked |
Connection | keep-alive |
Vary | Accept-Encoding |
Access-Control-Allow-Headers | Origin, X-Requested-With, Content-Type, Accept |
Access-Control-Allow-Origin | * |
Cache-Control | no-cache |
X-XSS-Protection | 1; mode=block |
X-Frame-Options | DENY |
X-Content-Type-Options | nosniff |
Strict-Transport-Security | max-age=31536000; includeSubdomains;preload |
X-Permitted-Cross-Domain-Policies | master-only |
Referrer-Policy | no-referrer-when-downgrade |
Content-Security-Policy | upgrade-insecure-requests |
Content-Encoding | gzip |