-pkx3WFeDBOxeNAxxD1sPPW429iBz7XJhBVeXQ== x-xss-protection: 1; mode=block referrer-policy: origin-when-cross-origin content-security-policy: default-src 'self' x-content-type-options: nosniff strict-transport-security: max-age=31536000; includeSubDomains permissions-policy: geolocation=(self), microphone=() set-cookie: strict X-Firefox-Spdy: h2