Access-Control-Allow-Methods: POST, PUT, GET, DELETE, OPTIONS Access-Control-Allow-Origin: * Cache-Control: max-age=0, no-cache, no-store, must-revalidate Connection: keep-alive Content-Type: text/html; charset=UTF-8 Date: Thu, 05 Oct 2017 09:50:47 GMT Expires: -1 Pragma: no-cache Referrer-Policy: origin Strict-Transport-Security: max-age=31536000; includeSubDomains; preload Transfer-Encoding: chunked X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-Xss-Protection: 1; mode=block