HTTP/1.1 200 200 Content-Length: 0 Connection: keep-alive Server: nginx Date: Mon, 09 Jun 2025 11:38:22 GMT X-Application-Context: application Set-Cookie: JSESSIONID=BD84B5E6516E2C1B3CC654D10DE7E9DB; Path=/; HttpOnly X-Frame-Options: SAMEORIGIN Frame-Options: SAMEORIGIN Referrer-Policy: strict-origin-when-cross-origin X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Permitted-Cross-Domain-Policies: master-only Strict-Transport-Security: max-age=31536000;includeSubdomains; preload X-Download-Options: SAMEORIGIN Content-Security-Policy: default-src * 'unsafe-inline' 'unsafe-eval' data: https: ;frame-ancestors 'self'