Apache
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa37dd2db492eb743ebbd7f0c0cdef2a19a5e28dcda
GraphQL introspection enabled at /graphql Types: 55 (by kind: ENUM: 10, INPUT_OBJECT: 6, OBJECT: 33, SCALAR: 6) Operations: - Query: Query | fields: me, product, products, shopInfo, shoppingCart - Mutation: Mutation | fields: addToCart, loginWeb, removeFromCart, removeFromWaitlist, updateCartQuantity Directives: deprecated, include, skip (total: 3)
Open service 151.101.130.132:443 · brassprism.com
2026-01-10 00:16
HTTP/1.1 200 OK Connection: close Content-Type: text/html; charset=UTF-8 Server: Apache Cache-Control: no-cache, private Content-Security-Policy-Report-Only: default-src 'self'; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; img-src * data: blob: android-webview-video-poster:; font-src * data:; connect-src * blob:; media-src * blob:; frame-src * blob: navigate:; worker-src 'self' blob:; frame-ancestors *; form-action 'self' www.facebook.com tr.snapchat.com pos.commentsold.com; object-src 'none'; manifest-src *; child-src 'self' blob:; report-uri https://o43862.ingest.sentry.io/api/239693/security/?sentry_key=deb2fc6b7d104f7ea6241356c26c14d0 x-robots-tag: all X-Request-Id: f38f5fbe-5e82-441f-bcd6-d80575cf089f Set-Cookie: laravel_session=eyJpdiI6IlJOWjVZT2EzRis3UjRWQXdsTnBjUGc9PSIsInZhbHVlIjoiNllVMUhNRmIyNlVCTDR2NWRJZWFRMi9NZGVYL3NsSEhaQlZjd2F4OCtDUFZBYTAwMDZocVlnekVpdDVsWEloYVI1enIyNkErenk0Y2tkNUd2NGduK2ZibVJXQk4vcVQxSWFqMW0xb1JPeGI4Z05Xc29CSkF5L2oxa3E1aVZTRjQiLCJtYWMiOiI5NGU5NzM0ODc5OWZjY2JkMDA3NGVkMDQzMmI5ODRlMGI1YjY3NzZlNTRhMDY5MGM1MmViZjI2YmQxNmFiYmNiIiwidGFnIjoiIn0%3D; expires=Wed, 11 Mar 2026 00:16:18 GMT; Max-Age=5184000; path=/; secure; httponly; samesite=none Set-Cookie: G33xw4EgcnVAOjDjwiQBNDNBKjihK3ZF51wQj2jD=eyJpdiI6IlQ3T0U1WGFaMCtlUFZGNGFqRlV1a3c9PSIsInZhbHVlIjoiTWlqTDJqbHZPVkl1MkZpNGNQMGVxajBtNmRhTzhyRzlIV1R3b084d013cmxSTjRtbTg3Uzh3MHNsZkNRRWgxSWxLQ1hNZEJERmlRcGlsTVNzNHFhUnhnWERXMmNyWUVEUi9tRnQwQVpqaWwrYjh4eDI4MytieUFaSWh0bjBhdy8zY3dxMTNmSm5HTk5WSlYwSkxzUHBKVEJPOHZjRG1oSXBUYzNjS3l4bFdJeFFySElYWGZKVGhaazhsOG1YVmFEdDIxdVd0RTF4Q0F0bDNFQVlMSzB4aWF0RncyNGVLS090c3laT2lwYWFpNm52Y2hhY2o2aER3bnFWNWpKU0I0Z2M1M2c4ZklQbitkMXAyUm1ld1FOQ1JHbnEzaXNEcmt3QjhoREZpaG9LN2phdnkzeXJXaUxnNThNRzNxbS9ENGZiZ3I3SCtLL0lpQXBSNXdXVHRoWXE3ZG10Z05YTTZPcFhwZUgzSGcvVkdVdmcvMW1BVVBNNXdLaXBMS2szNzJsZVUyL2JzL1BmYkl6QzZNUlZCRU1lTG4xMEFIMmtIVkdoenp0K2FwV1FUWWxuMk4wT2dBaFlmWGVTVkhsUDVyQjlsMXhUWU04eU5FaFpQWWFqdFlwb2JJai9xZUtCcklyaEhUTmVnQno3aHlUNjkxU0N5RFlRM2o3dXpLRUliZFMiLCJtYWMiOiIwMGQyZDM0ZDdmMjY2NTkyODk5YjU3MTcwZDgyNWNjNDY2NTJlZDdlODgyMTVlYzE4NmFjYWRmNzU5NThlNGI4IiwidGFnIjoiIn0%3D; expires=Wed, 11 Mar 2026 00:16:18 GMT; Max-Age=5184000; path=/; secure; httponly; samesite=none Access-Control-Allow-Origin: * Access-Control-Allow-Methods: POST, GET, OPTIONS, DELETE, PUT Access-Control-Max-Age: 1000 Access-Control-Allow-Headers: x-requested-with, Content-Type, origin, authorization, accept, client-security-token, Accept-Encoding Accept-Ranges: bytes Via: 1.1 varnish, 1.1 varnish X-Cacheable: NO:Set-Cookie Date: Sat, 10 Jan 2026 00:16:18 GMT X-Served-By: cache-chi-klot8100061-CHI, cache-lcy-egml8630090-LCY X-Cache: MISS, MISS X-Cache-Hits: 0, 0 X-Timer: S1768004179.538596,VS0,VE307 Vary: Accept-Encoding Strict-Transport-Security: max-age=900 transfer-encoding: chunked
Open service 151.101.130.132:443 · brassprism.com
2026-01-02 20:04
HTTP/1.1 200 OK Connection: close Content-Type: text/html; charset=UTF-8 Server: Apache Cache-Control: no-cache, private Content-Security-Policy-Report-Only: default-src 'self'; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; img-src * data: blob: android-webview-video-poster:; font-src * data:; connect-src * blob:; media-src * blob:; frame-src * blob: navigate:; worker-src 'self' blob:; frame-ancestors *; form-action 'self' www.facebook.com tr.snapchat.com pos.commentsold.com; object-src 'none'; manifest-src *; child-src 'self' blob:; report-uri https://o43862.ingest.sentry.io/api/239693/security/?sentry_key=deb2fc6b7d104f7ea6241356c26c14d0 x-robots-tag: all X-Request-Id: 1c96e0c3-2bc5-4266-949a-8fed4adae8db Set-Cookie: laravel_session=eyJpdiI6IjUwR2lUS0pJemFscHBJbnRVcTdtbXc9PSIsInZhbHVlIjoid29zTnFxQ2VQZDZ4d0orT0NsQ2NzcU15d1ZZTjVoYkx2WlRsK2lWRkcweTdjN3Vab01GM1Ryb1pvRzFNQTRSVFVFQkI3M2lnT0JObkVlbEVDQzd0VitqYTVsemkwaExWNG1MQnFMVGNUVGtLSUFvKzdNaWVHeXVhUFY3aS9xRzYiLCJtYWMiOiIxZGVlZTc2YTQ2ZGQ3NjRhMzE2OTI4NjI4NzgyZTllMWI4M2E2YzQ5M2UzYWQyMWNiYjVkNTQzNmMzN2FhZTI3IiwidGFnIjoiIn0%3D; expires=Tue, 03 Mar 2026 20:04:12 GMT; Max-Age=5184000; path=/; secure; httponly; samesite=none Set-Cookie: hMgwdVY5Iaadu2NPRXvGOLEDwmUcjkVpVajqwsUW=eyJpdiI6InQ4bjBsOFR2a2xXWFMrNEJjZUJEd1E9PSIsInZhbHVlIjoibXkrTnQ1bitTSVFRdWJWT0tEQWVDME4rbTkyZHN2ZHZqdU1mSW1Pa1BkS3lJdC85eWR5Y1U2U0pNZmdEZXh6TExPdlI1OGs3aEljZnk2bU1vTlM2TzYyREVodkZkVEVnQUFFOERMS2Fpejgrd2RkQ3duL3JGTTBLTXJQZXRsQ3JWanFMRVRiK0Y1VXNuVmgveTFSMXJSNXdQOFF0aEZMQWwrOTRzaXR3Q0JDeFdMTzArSzIyZEwxWUNURUF5bnNRbGYzSU1TTVJGSlYvT0hZT3ZCb2txMFlhaXJZb3YzcU1GY2lKNkw5NzRZRXE3akdZMnRwWlBCQkt0RVAzMFZyWHU2R2pjc0hTUGYwWWpBVFRuSG1NU1RseUVBQUJxMkFibm94U3pSaWZBa3c5UDZUQXg1cmZyQjl5Tmo2WEFpNmtMWUVEK1hnMnZtaUZCSGtlZVNSL1lmSmsxRkx6TDhpZW1qaVF6dG9ncHZrY25DWi9UZ2R0ZEhFbjhxVUJUV1R1cHovVWRBbW9EUHN3VVJweWFTL281dzlQRVFCZ1RNbHJFRnJWbE9RcmxUQWFSN2VZOCt1Q2dRcW40TVZXMUJwVVozNU1qd2JDNVJFb29pWlRFQlEvamxocE9DbEZLZmxLaHgwRzRjbUVpd0JnVnRKdnVhRXhyT1R2OTBzeTYxcWIiLCJtYWMiOiJlZGUwNTczNmU1ZjIzYWM2NDM4ZGFmODY2ZTIzY2VkM2MxNTdiN2JhNWNjN2QxZGYyMGMzNzUzOTM1YzViMTQ1IiwidGFnIjoiIn0%3D; expires=Tue, 03 Mar 2026 20:04:12 GMT; Max-Age=5184000; path=/; secure; httponly; samesite=none Access-Control-Allow-Origin: * Access-Control-Allow-Methods: POST, GET, OPTIONS, DELETE, PUT Access-Control-Max-Age: 1000 Access-Control-Allow-Headers: x-requested-with, Content-Type, origin, authorization, accept, client-security-token, Accept-Encoding Accept-Ranges: bytes Via: 1.1 varnish, 1.1 varnish X-Cacheable: NO:Set-Cookie Date: Fri, 02 Jan 2026 20:04:12 GMT X-Served-By: cache-chi-kigq8000085-CHI, cache-fra-eddf8230042-FRA X-Cache: MISS, MISS X-Cache-Hits: 0, 0 X-Timer: S1767384252.140165,VS0,VE320 Vary: Accept-Encoding Strict-Transport-Security: max-age=900 transfer-encoding: chunked
Open service 151.101.130.132:443 · brassprism.com
2025-12-23 08:45
HTTP/1.1 200 OK Connection: close Content-Type: text/html; charset=UTF-8 Server: Apache Cache-Control: no-cache, private Content-Security-Policy-Report-Only: default-src 'self'; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; img-src * data: blob: android-webview-video-poster:; font-src * data:; connect-src * blob:; media-src * blob:; frame-src * blob: navigate:; worker-src 'self' blob:; frame-ancestors *; form-action 'self' www.facebook.com tr.snapchat.com pos.commentsold.com; object-src 'none'; manifest-src *; child-src 'self' blob:; report-uri https://o43862.ingest.sentry.io/api/239693/security/?sentry_key=deb2fc6b7d104f7ea6241356c26c14d0 x-robots-tag: all X-Request-Id: dfac020d-6639-4541-8fed-83640d0b19be Set-Cookie: laravel_session=eyJpdiI6IkVjZGxWVjNXemdNaDl3SHVVZmVHTFE9PSIsInZhbHVlIjoiYkRGZWRoaUtabW5kTFk3OS9sdnBMYy85WFl1NFMxMWphOVhaaWhET3NKWTNZWFAvWUJzaUtTNnFaWG1xd2RzbWI5K0pUK1JGK3crM3ArenNQWHMxZzZHSWxidXhUam9KOFRtOGdEejJ0UXlZTnV6Ym9QMzJmWitncU5HVUVNWFMiLCJtYWMiOiJmMWQ1OGM5YzRmZDYyYTIxNGJlNGMxYmFhMWFhMzhlZWRmMzA5YjliNDM3ZDg1MWZkYWMxMjlkZjliODkxNDY1IiwidGFnIjoiIn0%3D; expires=Sat, 21 Feb 2026 08:45:53 GMT; Max-Age=5184000; path=/; secure; httponly; samesite=none Set-Cookie: Yz6XeDVDCnMAO3F0RvJtMcaNF07DBxAb1QOWJwIM=eyJpdiI6IjZtTGZacWlDQk5ZTEtjY250VDNNeEE9PSIsInZhbHVlIjoiTUppc05XMEt3SWRzZ3JheHZaSTkrMEM3eWpIUHdSczFMY0ovbFZaNVp2Z28rVFlwb0l3OUtOQ1AyYlVueFRvenZqR1JRbVhZRlZoUjRhQ1ZHb241NzdPZEdVMnpRQ0RJbWYwQ2h2VVdkWmxoTWVCTVlTVThrTmw3cEd1ejFXRC94U0FiZm9sUnZKUHZHNkZ0Y25kZVpjdU10eHQ1cW85WllRNnlFYUhmdHE1MmJydVBYOXRnMVUzT0xVZG1VSjgyWitrWVRKQUlNNGlqUWorYVZEMXBTQVpUMWZkTDE0NHlwN2poRllRWEtWbWtha1VkQnJCK1B1VlRuNW9UMElCMUE2TzNkRHVKUkI0UlJaZkVOY1AwMVZuNU5GRlZWaTFXNXlaWitZdjUwRWhNV0RxYUFDQ1NQcnNJWndtY2dRK0twSUxDbHV2djVJSExDWnlBZjFhbEJUOVNJaXUvWkswWkwzZ0wrc1V5VDFOemc1Wm9tTjlwSGlVK1NJQnJuVHhvdm80N3dCaEtISURxbExsQTJ5ZXdtSzIvWnBFWlFMT0FlYzBNSzBJNGdtcXFCZWc0eWdlUWI5dHNhMU9RanpxNWgrc2ZjZWtlZFJBQUxCQWwxdHE0djVHZU1HWWhqM2hkZHVjemVyNE8zVFJOdWhEcFVTekNDNmN4ZDZoMHVQYkUiLCJtYWMiOiI2OGU2N2E4NThjNmVjZTM5YzlmMmVhNTI1MGVjZjA4MmY5MDBjMGI5OTgxZjk1ZTE0ZDUxNDA5MTBiMGM0ZTViIiwidGFnIjoiIn0%3D; expires=Sat, 21 Feb 2026 08:45:53 GMT; Max-Age=5184000; path=/; secure; httponly; samesite=none Access-Control-Allow-Origin: * Access-Control-Allow-Methods: POST, GET, OPTIONS, DELETE, PUT Access-Control-Max-Age: 1000 Access-Control-Allow-Headers: x-requested-with, Content-Type, origin, authorization, accept, client-security-token, Accept-Encoding Accept-Ranges: bytes Via: 1.1 varnish, 1.1 varnish X-Cacheable: NO:Set-Cookie Date: Tue, 23 Dec 2025 08:45:53 GMT X-Served-By: cache-chi-klot8100063-CHI, cache-vie6374-VIE X-Cache: MISS, MISS X-Cache-Hits: 0, 0 X-Timer: S1766479553.267301,VS0,VE296 Vary: Accept-Encoding Strict-Transport-Security: max-age=900 transfer-encoding: chunked
Open service 151.101.130.132:443 · brassprism.com
2025-12-21 06:29
HTTP/1.1 200 OK Connection: close Content-Type: text/html; charset=UTF-8 Server: Apache Cache-Control: no-cache, private Content-Security-Policy-Report-Only: default-src 'self'; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; img-src * data: blob: android-webview-video-poster:; font-src * data:; connect-src * blob:; media-src * blob:; frame-src * blob: navigate:; worker-src 'self' blob:; frame-ancestors *; form-action 'self' www.facebook.com tr.snapchat.com pos.commentsold.com; object-src 'none'; manifest-src *; child-src 'self' blob:; report-uri https://o43862.ingest.sentry.io/api/239693/security/?sentry_key=deb2fc6b7d104f7ea6241356c26c14d0 x-robots-tag: all X-Request-Id: 452e6d97-4700-4b5f-b89f-dc144e31efda Set-Cookie: laravel_session=eyJpdiI6IloyLzFnc0JVVDRibVF6dXhFWkp0WFE9PSIsInZhbHVlIjoiU21VbVViZm95SDVrNWhGejlxQkloSW1sbCsxOUt0eG5OczV4bXpZZ2ZzRnltREcvS281RndmbTFtdXUxOTZGdGQxV2x1WTFUV3U4VUZNNWo2RS9Mc1pUZFN0dTV6Z1hldWVPdjF4cm1rbnMxSk9xOEZFbnpEOTFBSnVOQmkyVjIiLCJtYWMiOiI1YmE5MjM1ZTk2NTgwMDBiMWUwZmIzOTdiZjAxNzVjZGIyZDc3OTcyOWI0YjMwNjU3NGYwNTZkMTI2NTcyNWNiIiwidGFnIjoiIn0%3D; expires=Thu, 19 Feb 2026 06:29:22 GMT; Max-Age=5184000; path=/; secure; httponly; samesite=none Set-Cookie: IFIblg9kiv8A9zcxx6YpFBXhQ3H1Z9qFRzWn10fZ=eyJpdiI6ImU1L0NQTHllVG1GazJQMXk1YWt6UlE9PSIsInZhbHVlIjoiWVBPT3pNZFRpcXRYdSsza0JZdUR1Wjl3L3dCS1RoRjF4MU56OXlDNjJkWDh2bWJhaERzclEyTUYrdzhOdnIrK1orL2tmL2dIREdEWFJKQU5pN1BRTVZpTERjRm8ybCtGMXRUUVpnaUtiSkVBTFdGRmRMa0x1dnVlV2pFQXpxZmt3QnJaN3pCRk9OOFp2OEJBR1kvbkQ2TXM1NGJRRzBtVjRkRytTNDExcVJaMDduMlk2Ym9yZS9HejRsMXNIQ0E5dkRJR1JvUkJ6WHVaa0N2MlQyendrMmx2b3RLVUtJTXhZUXA4QUIwa1FkeGgrWDJuSmpOYjlaT2I2V2Zrb1VHWWtzYWdLZjdiakV1bVc5OHFZY0RMR0daMGdTS3VaS2V1NWc0clpRU1d5UFA2dVJzM1V0WHZHK08rVm1GZjhlQUxYWkgvSGtYZ3lrUlllRytyaTVEaitxMmd1dVgvdllmWUJmeGltNGtEZXVTNm14Mks3bXI5U25oelorVFJiNmFvalo1QlI3TTZCRWRKY1cwMFhtNE1YeGFKZnAzWjBWVHlHcmdJZWFRL1RrV0wxNHRWNTNpSTRoOGk4dlE4cS91bmJTeThIZXBoQTZYVUJ3NmdJd0Vvc2VlOTlEMWNpaUhwU1V6Z1lEMFRJS1o4YW9vaGVuNnZyS0drbWNjamxqaUoiLCJtYWMiOiJkYmVkNWJkZmE0YTljZWUyNGY0NmE4OGM3NmM1NWE2ZmMyM2ZhN2EzY2E0Nzk0YTZlNzk0MzNiMzQ1N2I1MzI0IiwidGFnIjoiIn0%3D; expires=Thu, 19 Feb 2026 06:29:22 GMT; Max-Age=5184000; path=/; secure; httponly; samesite=none Access-Control-Allow-Origin: * Access-Control-Allow-Methods: POST, GET, OPTIONS, DELETE, PUT Access-Control-Max-Age: 1000 Access-Control-Allow-Headers: x-requested-with, Content-Type, origin, authorization, accept, client-security-token, Accept-Encoding Accept-Ranges: bytes Via: 1.1 varnish, 1.1 varnish X-Cacheable: NO:Set-Cookie Date: Sun, 21 Dec 2025 06:29:22 GMT X-Served-By: cache-chi-kigq8000103-CHI, cache-fra-eddf8230125-FRA X-Cache: MISS, MISS X-Cache-Hits: 0, 0 X-Timer: S1766298562.179116,VS0,VE320 Vary: Accept-Encoding Strict-Transport-Security: max-age=900 transfer-encoding: chunked
Open service 151.101.130.132:443 · brassprism.com
2025-12-19 02:22
HTTP/1.1 200 OK Connection: close Content-Type: text/html; charset=UTF-8 Server: Apache Cache-Control: no-cache, private Content-Security-Policy-Report-Only: default-src 'self'; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; img-src * data: blob: android-webview-video-poster:; font-src * data:; connect-src * blob:; media-src * blob:; frame-src * blob: navigate:; worker-src 'self' blob:; frame-ancestors *; form-action 'self' www.facebook.com tr.snapchat.com pos.commentsold.com; object-src 'none'; manifest-src *; child-src 'self' blob:; report-uri https://o43862.ingest.sentry.io/api/239693/security/?sentry_key=deb2fc6b7d104f7ea6241356c26c14d0 x-robots-tag: all X-Request-Id: 02dd0489-91a8-4378-8159-06e1cf61a527 Set-Cookie: laravel_session=eyJpdiI6ImFwc1dZSU9xSE5IOXpibUVENFIzTkE9PSIsInZhbHVlIjoiVWwyblpqcXZzcGhYY3YrTmpQdHREU2pveTUvL1Qyd3dkdUN5NWRybkNhMkp6cllCTW4yYmc5K0ZXUXdrRkJ3NHoremlhOFVMOGpJWTFsN05JSUMzdHRaVkRqU3lSL3lFbU4vR1l1VWNiYzNMRHdBVm42QVFlT0M3bXAwWmVmRnMiLCJtYWMiOiJiMjMxZDIwMTFjOGM5ZThmZmRmOTk3YjQ5NDEzYjY3ZTMwNGZhMGM5NDk5NzI4OTY1NmZkOWYzNmJlYWRiMzQzIiwidGFnIjoiIn0%3D; expires=Tue, 17 Feb 2026 02:22:14 GMT; Max-Age=5184000; path=/; secure; httponly; samesite=none Set-Cookie: Go7uc7fxyEthGcuNI10Lys93M7wyqRbEJ9OgGidv=eyJpdiI6IkViZFBqNVNsbzZsZEMyZjEraEJ4Mmc9PSIsInZhbHVlIjoiVWIvdVFsNDVHV3NaZW01STNTWlVqM1lJSHVqSUN6Uy90WjIwOUtWQ3JKeGNmNlBXdENRV2ZES3NOdEltakVMRUdhcGhZY3hYVEVYOGFZdTV6V2ZWYk9NMU1aZG1DU0NJQk9RTDNhUXFsRHB1V25nR0xVa0VqNmZJbXpKdEVtUVZXMUNVNERXZ0pFQ0R4ZDRGSXpWN2JEL0RFc3JGa0xaYnRIaE1xT2IrcVFMdEpjYkZKRGxkaWNaaWhpNUdPL1N5WnBEQVBhN2kvYlFEWTFOZW03anhGS1ZTQXF2ZExGcnh6d0VSYUtTVkN5Y25GTWRBNHJQM0ZXQXBrZFBkaTVaVGlqZ094Z1NXbnBrZ1RqVFFDOUo4T0d3bVZTMjlRYTJTVHNSVGluVWxvdit6U3lYUGxFeDVSbDM3QzJaajZONCtQUlE5cEh1UEtOOE16bmQ4OXVvVUV4M09iMFZzWFMrUElENFo4UDBqYXJWQnY1RVZTaUx5dEluUElOVlFMSDQ3amdMaGVEV0F0a3RxSmpQM3NzdjRDR2VnTlVnakZ3KzJzbDJMeE5sYmpEMEdkalZrbkZQZENKdTZpMEd2Vzg2QTJUeDczTmp5UVBEQUcvdERxeDdRMnFFMG1UYyt1cWlVNFBLWFJ1NEtIY0puWmV3RnVmSTlSd2pvbFRnVENJMXEiLCJtYWMiOiJmMGFiODM0ZDM4M2IwYmFlMDNmM2JlNjI4MjkwN2JlMzA2ZGZmMTljMzM4YzgyMzhjZjAyNWJjZDU3ZDJiNGYyIiwidGFnIjoiIn0%3D; expires=Tue, 17 Feb 2026 02:22:14 GMT; Max-Age=5184000; path=/; secure; httponly; samesite=none Access-Control-Allow-Origin: * Access-Control-Allow-Methods: POST, GET, OPTIONS, DELETE, PUT Access-Control-Max-Age: 1000 Access-Control-Allow-Headers: x-requested-with, Content-Type, origin, authorization, accept, client-security-token, Accept-Encoding Accept-Ranges: bytes Via: 1.1 varnish, 1.1 varnish X-Cacheable: NO:Set-Cookie Date: Fri, 19 Dec 2025 02:22:14 GMT X-Served-By: cache-chi-klot8100040-CHI, cache-rtm-ehrd2290055-RTM X-Cache: MISS, MISS X-Cache-Hits: 0, 0 X-Timer: S1766110934.011917,VS0,VE308 Vary: Accept-Encoding Strict-Transport-Security: max-age=900 transfer-encoding: chunked