Cache-Control: private, no-cache, no-store, must-revalidate
content-security-policy: default-src * data: blob:;script-src *.facebook.com *.fbcdn.net *.facebook.net *.google-analytics.com *.virtualearth.net *.google.com 127.0.0.1:* *.spotilocal.com:* 'unsafe-inline' 'unsafe-eval' fbstatic-a.akamaihd.net fbcdn-static-b-a.akamaihd.net *.atlassolutions.com blob: data: 'self';style-src data: blob: 'unsafe-inline' *;connect-src *.facebook.com *.fbcdn.net *.facebook.net *.spotilocal.com:* *.akamaihd.net wss://*.facebook.com:* https://fb.scanandcleanlocal.com:* *.atlassolutions.com attachment.fbsbx.com ws://localhost:* blob: *.cdninstagram.com 'self' chrome-extension://boadgeojelhgndaghljhdicfkmllpafd chrome-extension://dliochdbjfkdbacpmhlcpmleaejidimm;
Vary: Origin
Date: Tue, 31 Oct 2017 14:07:50 GMT
Access-Control-Allow-Credentials: true
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Access-Control-Allow-Origin: https://www.facebook.com
Access-Control-Expose-Headers: X-FB-Debug, X-Loader-Length
Strict-Transport-Security: max-age=15552000; preload
access-control-allow-method: OPTIONS
HTTP/1.1 200 OK
Vary: Accept-Encoding
Transfer-Encoding: chunked
X-XSS-Protection: 0
Connection: keep-alive
Pragma: no-cache
X-FB-Debug: cDf6IMUKM9Xca9778gv1KAf1KLLv0Y2ow7ppUPcJbDr6xP9PyQMQMqKTm7vMgipV5XH3FBFtpzB/+0SSy1OkBQ==
Expires: Sat, 01 Jan 2000 00:00:00 GMT
X-Frame-Options: DENY