
Strict-Transport-Security: max-age=63072000; includeSubDomains CSP: script-src 'nonce-random123' 'unsafe-inline' https:; object-src 'none'; base-uri 'none'; report-uri https://reporting.example.com; Access-Control-Allow-Origin: https://developer.mozilla.org Vary: Origin
