Strict-Transport-Security: max-age=31536000; preload
X-Cache-L2: 322
Date: Mon, 01 May 2017 13:37:18 GMT
Content-Type: text/html; charset=UTF-8
HTTP/1.1 200 OK
Connection: keep-alive
Cache-Control: private, no-cache, no-store, proxy-revalidate, no-transform
Link: <http://mwg.vn/wp-json/>; rel="https://api.w.org/", <http://mwg.vn/>; rel=shortlink
Pragma: no-cache
Vary: Accept-Encoding
Access-Control-Allow-Origin: mwg.vn
Transfer-Encoding: chunked
Set-Cookie: SvID=v322|WQc6E|WQc6E; path=/
X-Content-Type-Options: nosniff
Content-Security-Policy-Report-Only: default-src 'self'; script-src 'self' 'unsafe-inline' mwg.vn https://*.google-analytics.com https://*.facebook.net; img-src 'self' data: https: https://*.thegioididong.com https://*.google-analytics.com https://*.facebook.com https://*.googleapis.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; frame-src 'self' https://*.facebook.com; object-src 'self'
Referrer-Policy: no-referrer
Keep-Alive: timeout=15
Server: MWG
Public-Key-Pins: pin-sha256="XR5ZMWvP4K5+SMiaLIPRLZGgGdlXd9s2w13X7rJ1muw="; pin-sha256="ETrxfY/aVptAHxW1VmC2WjDv0VLyOmN9vfVO45quBtg="; pin-sha256="q5hJUnat8eyv8o81xTBIeB5cFxjaucjmelBPT2pRMo8="; pin-sha256="mZMEJHpiZuw/pqz3pYqqkxVx8W7aX4gKHItyz2y7AxU="; max-age=2592000; preload
X-XSS-Protection: 1; mode=block
Vary: Accept-Encoding,User-Agent
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff