HTTP/1.1 200 200 Content-Length: 0 Connection: keep-alive Server: nginx Date: Thu, 10 Jul 2025 17:50:54 GMT X-Application-Context: application Set-Cookie: JSESSIONID=C71FAF0BE4B41579D2931253EBFCFFA9; Path=/; HttpOnly X-Frame-Options: SAMEORIGIN Frame-Options: SAMEORIGIN Referrer-Policy: strict-origin-when-cross-origin X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Permitted-Cross-Domain-Policies: master-only Strict-Transport-Security: max-age=31536000;includeSubdomains; preload X-Download-Options: SAMEORIGIN Content-Security-Policy: default-src * 'unsafe-inline' 'unsafe-eval' data: https: ;frame-ancestors 'self'