ontent-type-options: nosniff strict-transport-security: max-age=31536000; includeSubDomains permissions-policy: geolocation=(self), microphone=() set-cookie: strict X-Firefox-Spdy: h2