Access-Control-Allow-Credentials: true Access-Control-Allow-Method: OPTIONS Access-Control-Allow-Origin: https://m.facebook.com Access-Control-Expose-Headers: X-FB-Debug, X-Loader-Length Cache-Control: private, no-cache, no-store, must-revalidate Content-Security-Policy: default-src * data: blob:;script-src *.facebook.com *.fbcdn.net *.facebook.net *.google-analytics.com *.virtualearth.net *.google.com 127.0.0.1:* *.spotilocal.com:* 'unsafe-inline' 'unsafe-eval' fbstatic-a.akamaihd.net fbcdn-static-b-a.akamaihd.net *.atlassolutions.com blob: data: 'self';style-src data: blob: 'unsafe-inline' *;connect-src *.facebook.com *.fbcdn.net *.facebook.net *.spotilocal.com:* *.akamaihd.net wss://*.facebook.com:* https://fb.scanandcleanlocal.com:* *.atlassolutions.com attachment.fbsbx.com ws://localhost:* blob: *.cdninstagram.com 'self'; Content-Type: text/html; charset=utf-8 Date: Thu, 05 Oct 2017 17:21:22 GMT Expires: Sat, 01 Jan 2000 00:00:00 GMT Pragma: no-cache Public-Key-Pins-Report-Only: max-age=600; pin-sha256="WoiWRyIOVNa9ihaBciRSC7XHjliYS9VwUGOIud4PB18="; pin-sha256="k2v657xBsOVe1PQRwOsHsw3bsGT2VzIqz5K+59sNQws="; pin-sha256="gMxWOrX4PMQesK9qFNbYBxjBfjUvlkn/vN1n+L9lE5E="; pin-sha256="q4PO2G2cbkZhZ82+JgmRUyGMoAeozA+BSXVXQWB8XWQ="; report-uri="http://reports.fb.com/hpkp/" Set-Cookie: reg_fb_ref=https%3A%2F%2Fm.facebook.com%2F%3Fzero_e%3D6%26zero_et%3D1507224142%26refsrc%3Dhttps%253A%252F%252F0.facebook.com%252F; path=/; domain=.facebook.com; secure; httponly sb=EmrWWSIQ2U524bpsw_CvCRj6; expires=Sat, 05-Oct-2019 17:21:22 GMT; Max-Age=63072000; path=/; domain=.facebook.com; secure; httponly Status: 200 Strict-Transport-Security: max-age=15552000; preload Vary: Origin Accept-Encoding X-Content-Type-Options: nosniff X-Fb-Debug: 1TpSFlc6buWWXLA2SCndnS0F7jfj1lpvOdNcc2KvnJgJ9kyXCrsVNlT8OCG3H0ZURpE0o2kaVlnopIptWh3E9A== X-Frame-Options: DENY X-Xss-Protection: 0