HTTP/2 200 content-security-policy: default-src 'self'; base-uri 'self'; connect-src 'self'; frame-ancestors 'none'; frame-src 'none'; object-src 'none'; script-src 'self'; style-src 'self' 'nonce-Hy2h185wxuwadnlopIKIB21xZPlglILc' 'sha256-47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=' content-type: text/html; charset=utf-8 date: Tue, 14 Apr 2026 03:26:00 GMT permissions-policy: accelerometer=(), autoplay=(), camera=(), display-capture=(), geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), screen-wake-lock=(), sync-xhr=(), xr-spatial-tracking=(), interest-cohort=() referrer-policy: strict-origin-when-cross-origin strict-transport-security: max-age=15552000; includeSubDomains; preload x-content-type-options: nosniff x-dns-prefetch-control: off x-frame-options: SAMEORIGIN x-xss-protection: 1; mode=block content-length: 3760