Access-Control-Allow-Headers: Origin, X-Requested-With, Content-Type, Accept Access-Control-Allow-Origin: * Connection: keep-alive Content-Length: 9 Content-Type: text/html; charset=utf-8 Date: Thu, 05 Oct 2017 12:35:25 GMT Etag: W/"9-+/wSCx9uyQlHanaiMb7FcI2OZuQ" Strict-Transport-Security: max-age=15552000; includeSubDomains X-Content-Type-Options: nosniff X-Dns-Prefetch-Control: off X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Xss-Protection: 1; mode=block