Strict-Transport-Security: max-age=31536000; includeSubDomains; preload X-Frame-Options: DENY X-Content-Type-Options: nosniff Referrer-Policy: strict-origin-when-cross-origin Cache-Control: no-cache, no-store, must-revalidate Pragma: no-cache Expires: 0 Accept-Ranges: bytes