HTTP/1.1 200 OK Server: nginx Date: Sun, 11 Jan 2026 19:21:50 GMT Content-Type: text/html; charset=UTF-8 Connection: keep-alive Vary: Accept-Encoding Access-Control-Allow-Methods: POST, PUT, GET, DELETE, OPTIONS Access-Control-Allow-Headers: Content-Type Strict-Transport-Security: max-age=31536000; includeSubDomains Set-Cookie: PHPSESSID=fpmuh03tb331j7rgem0evfjhu3; path=/ Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Link: ; rel="https://api.w.org/" Link: ; rel="alternate"; title="JSON"; type="application/json" Link: ; rel=shortlink Vary: Accept-Encoding Access-Control-Allow-Origin: * X-Frame-Options: allow-from * X-XSS-Protection: 1; mode=block Access-Control-Allow-Origin: * X-Frame-Options: SAMEORIGIN Access-Control-Allow-Methods: POST, PUT, GET, DELETE, OPTIONS Access-Control-Allow-Headers: Content-Type Strict-Transport-Security: max-age=31536000 Content-Security-Policy: default-src 'self'; connect-src *; font-src * data:; frame-src *; img-src * data:; media-src *; object-src *; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; X-Content-Type-Options: nosniff Referrer-Policy: strict-origin Permissions-Policy: geolocation=(),midi=(),sync-xhr=(),microphone=(),camera=(),magnetometer=(),gyroscope=(),fullscreen=(self),payment=()