HTTP /1.1 200 OK
Server: Apache-Coyote/1.1
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff
Set-Cookie: Path=/; HttpOnly; Secure
X-Download-Options: noopen
Content-Security-Policy: manifest-src 'self'
X-Permitted-Cross-Domain-Policies: value
X-Frame-Options: SAMEORIGIN
Referrer-Policy: origin
Strict-Transport-Security: value
Accept-Ranges: bytes
ETag: W/