/* X-Frame-Options: DENY X-Content-Type-Options: nosniff X-DNS-Prefetch-Control: off Referrer-Policy: no-referrer Permissions-Policy: interest-cohort=(), geolocation=(), camera=(), microphone=(), display-capture=(), web-share=() Content-Security-Policy: default-src 'self'; script-src 'none'; frame-ancestors 'none'; child-src 'none'; base-uri 'self'; object-src 'none'; require-trusted-types-for 'script'