HTTP/1.1 200 OK
Content-Security-Policy: default-src 'self';script-src 'self';style-src 'self' 'unsafe-inline';img-src 'self' data: blob:;connect-src 'self';font-src 'self' data:;object-src 'none';frame-ancestors 'none';base-uri 'self';form-action 'self';script-src-attr 'none'
Cross-Origin-Opener-Policy: same-origin
Cross-Origin-Resource-Policy: same-origin
Origin-Agent-Cluster: ?1
Referrer-Policy: strict-origin-when-cross-origin
X-Content-Type-Options: nosniff
X-DNS-Prefetch-Control: off
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-XSS-Protection: 0
Vary: Origin
Access-Control-Expose-Headers: X-RateLimit-Limit,X-RateLimit-Remaining,Retry-After
Accept-Ranges: bytes
Cache-Control: public, max-age=3600
Last-Modified: Thu, 10 Sep 2026 17:23:13 GMT
ETag: W/"94b-1a08c584fe8"
Content-Type: text/html; charset=UTF-8
Content-Length: 2379
Date: Tue, 15 Sep 2026 21:55:32 GMT
Connection: keep-alive
Keep-Alive: timeout=5