
Strict-Transport-Security: max-age=63072000; includeSubDomains
CSP: script-src 'nonce-random123' 'unsafe-inline' https:;
object-src 'none';
base-uri 'none';
report-uri https://reporting.example.com;
HTML:
Cross-Origin-Embedder-Policy: require-corp
Cross-Origin-Resource-Policy: cross-origin
Cross-Origin-Opener-Policy: unsafe-none
Content-Security-Policy: default-src 'self' http://example.com;connect-src 'none';
Content-Security-Policy: connect-src http://example.com/;script-src http://example.com/
Content-Security-Policy: require-trusted-types-for 'script';
trusted-types;
Access-Control-Allow-Origin: https://developer.mozilla.org
Vary: Origin
