Access-Control-Allow-Credentials: true Access-Control-Allow-Origin: * Connection: keep-alive Content-Length: 202 Content-Type: application/javascript; charset=utf-8 Date: Thu, 05 Oct 2017 15:52:39 GMT P3p: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSAo PSDo OUR BUS UNI NAV STA INT" Server: nginx Strict-Transport-Security: max-age=31536000; includeSubDomains Vary: Accept-Encoding, Origin X-Content-Type-Options: nosniff X-Xss-Protection: 1; mode=block; report=https://cspreport.mail.ru/xxssprotection