HTTP/1.1 200 OK Accept-Ranges: bytes Access-Control-Allow-Credentials: true Access-Control-Allow-Methods: GET, POST, OPTIONS Content-Length: 0 Content-Security-Policy: manifest-src 'self'; Content-Security-Policy: frame-ancestors 'self' Content-Type: text/html; charset=utf-8 Date: Mon, 16 Jun 2025 04:01:29 GMT Etag: "684f8c64-0" Frame-Ancestors: self Last-Modified: Mon, 16 Jun 2025 03:15:48 GMT Referrer-Policy: origin Server: nginx Set-Cookie: Path=/; HttpOnly; Secure X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Permitted-Cross-Domain-Policies: none X-Xss-Protection: 1;mode=block