ult-src 'self' 'unsafe-inline' content-type: image/gif date: Wed, 14 Jan 2026 10:57:54 GMT referrer-policy: same-origin server: Kestrel strict-transport-security: max-age=315360000; includeSubDomains; preload x-content-type-options: nosniff x-frame-options: DENY x-xss-protection: 1; mode=block content-length: 42 X-Firefox-Spdy: h2