HTTP/1.1 200 OK Access-Control-Allow-Headers: * Access-Control-Allow-Methods: * Access-Control-Allow-Origin: * Content-Length: 13 Content-Security-Policy: default-src 'self'; base-uri 'self'; connect-src 'self' https:; font-src 'self' data: https://fonts.gstatic.com; form-action 'self'; frame-ancestors 'none'; frame-src https:; img-src 'self' data: blob: https:; manifest-src 'self'; object-src 'none'; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline' Content-Type: text/plain; charset=utf-8 Date: Tue, 09 Jun 2026 19:49:41 GMT Permissions-Policy: camera=(), geolocation=(), microphone=(), payment=(), usb=() Referrer-Policy: strict-origin-when-cross-origin Via: 1.1 Caddy X-Content-Type-Options: nosniff X-Frame-Options: DENY Connection: close 72.195.34.60