HTTP/1.1 200 OKServer: nginxDate: Tue, 04 Oct 2022 16:36:56 GMTContent-Type: text/html; charset=utf-8Connection: keep-aliveX-Request-Id: 79be502b32e2e39f5d97a5d353158388Surrogate-Control: no-storeCache-Control: no-store, no-cache, must-revalidate, proxy-revalidatePragma: no-cacheExpires: 0Report-To: {"group":"csp-endpoint","max_age":10886400,"endpoints":[{"url":"/csp-logger"}]}Content-Security-Policy: report-uri /csp-logger;report-to csp-endpoint;default-src 'self' https://vanguardassets.bmstatic.com/assets/;connect-src 'self' https://vanguardassets.bmstatic.com/assets/ https://mc.yandex.fr https://mc.yandex.kz https://mc.yandex.by https://mc.yandex.ru https://mc.yandex.tr https://mc.yandex.com https://mc.yandex.md https://cognito-identity.us-east-1.amazonaws.com https://mobileanalytics.us-east-1.amazonaws.com https://stats.g.doubleclick.net https://www.facebook.com https://connect.facebook.net https://www.google-analytics.com https://api.rollbar.com https://ajax.googleapis.com https://wa.onelink.me https://wa.appsflyer.com http://api.webgains.io;style-src 'self' 'unsafe-inline' https://vanguardassets.bmstatic.com/assets/ https://tagmanager.google.com https://fonts.googleapis.com https://www.googletagmanager.com;script-src 'self' 'unsafe-inline' 'unsafe-eval' https://vanguardassets.bmstatic.com/assets/ https://app.link https://connect.facebook.net https://www.google-analytics.com https://ssl.google-analytics.com https://www.google.com https://www.googletagmanager.com https://www.googleadservices.com https://www.gstatic.com https://js.stripe.com https://mc.yandex.ru https://tagmanager.google.com https://websdk.appsflyer.com https://wa.onelink.me https://get4click.ru https://analytics.webgains.io;font-src 'self' https://vanguardassets.bmstatic.com/assets/ data: https://fonts.gstatic.com;img-src * 'self' 'unsafe-inline' https://vanguardassets.bmstatic.com/assets/ data: https://www.gstatic.com https://ssl.gstatic.com https://www.googletagmanager.com https://www.google-analytics.com https://stats.g.doubleclick.net;media-src * 'self' 'unsafe-inline' https://ssl.gstatic.com;frame-src 'self' https://*.bookmate.com https://*.bookmate.ru https://bookmate.com https://bookmate.ru https://bookmate.onelink.me https://www.facebook.com https://www.google.com https://www.googletagmanager.com https://js.stripe.com https://simplecast.com https://mc.yandex.ru;object-src 'none'X-DNS-Prefetch-Control: offExpect-CT: max-age=0X-Frame-Options: SAMEORIGINX-Download-Options: noopenX-Content-Type-Options: nosniffX-Permitted-Cross-Domain-Policies: noneReferrer-Policy: no-referrerX-XSS-Protection: 0set-cookie: _csrf=HpfMs1-OuzLd2gVPO1APneYP; Path=/X-Generated-With: LOVEContent-Encoding: gzip