HTTP/2 200 content-security-policy: default-src 'self' *; script-src 'self' 'unsafe-inline' 'unsafe-eval' *; img-src 'self' data: *; style-src 'self' 'unsafe-inline' *; font-src 'self' * data:; object-src 'self' *; frame-src 'self' *; worker-src 'self' *; connect-src 'self' *x-frame-options: SAMEORIGINpermissions-policy: geolocation=(), midi=(),notifications=(),push=(),sync-xhr=(),accelerometer=(), gyroscope=(), magnetometer=(), payment=(), camera=(), microphone=(), usb=()m xr=()m speaker=(self), vibrate=(), fullscreen=(self),strict-transport-security: max-age=31536000; includeSubDomains; preloadreferrer-policy: no-referrerx-content-type-options: nosniffx-xss-protection: 1; mode=blockvary: Accept-Encodingcache-control: max-age=0, no-cachecontent-type: text/html; charset=utf-8date: Sat, 27 Dec 2025 20:36:20 GMTserver: Apache