| Access-Control-Allow-Headers: | Authorization,Content-Type,Accept,Origin,Pragma,User-Agent,DNT,Cache-Control,X-Mx-ReqToken,Keep-Alive,X-Requested-With,If-Modified-Since, Authorization,Content-Type,Accept,Origin,Pragma,User-Agent,DNT,Cache-Control,X-Mx-ReqToken,Keep-Alive,X-Requested-With,If-Modified-Since |
| X-Robots-Tag: | noindex, nofollow |
| Content-Security-Policy: | default-src * data: 'unsafe-inline' 'unsafe-eval'; media-src * blob:;, default-src * data: 'unsafe-inline' 'unsafe-eval'; media-src * blob:; |
| Transfer-Encoding: | chunked |
| Cache-Control: | max-age=0, no-cache |
| Vary: | Accept-Encoding |
| X-Page-Speed: | 1.13.35.2-0 |
| Server: | nginx |
| Connection: | keep-alive |
| X-XSS-Protection: | 1, 1 |
| Access-Control-Allow-Credentials: | true, true |
| Date: | Fri, 20 Jul 2018 03:15:45 GMT |
| X-Content-Security-Policy: | default-src * data: 'unsafe-inline' 'unsafe-eval'; media-src * blob:;, default-src * data: 'unsafe-inline' 'unsafe-eval'; media-src * blob:; |
| P3P: | CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT |
| Access-Control-Allow-Methods: | POST,GET,PUT,DELETE,OPTIONS, POST,GET,PUT,DELETE,OPTIONS |
| Content-Type: | text/html; charset=UTF-8 |
| Access-Control-Allow-Origin: | *, * |
| X-WebKit-CSP: | default-src * data: 'unsafe-inline' 'unsafe-eval'; media-src * blob:;, default-src * data: 'unsafe-inline' 'unsafe-eval'; media-src * blob:; |