Submitted by nitori in technology
I don't think it really matters but just wanna put it out. Maybe check either caddy or nginx config for the directive sending the Vary: Accept-Encoding
and remove one of them if you want to lol
HEAD / HTTP/1.1
Host: jstpst.net
HTTP/1.1 200 OK
Alt-Svc: h3=":443"; ma=2592000
Cache-Control: max-age=0, must-revalidate, private, s-maxage=10
Content-Security-Policy: default-src 'self'; img-src 'self' data: ; script-src 'self' 'unsafe-inline' 'sha256-KiBJHYgQ3JksGRdlBaZEXVQ0UvSiVF+WF0BRuAzJPtg='; style-src 'self' 'unsafe-inline' 'sha256-5djBAhgU6lT6/IvDqBYV1J+3001Gap43QwbVwQ0EoTQ='
Content-Type: text/html; charset=UTF-8
Date: Tue, 23 Jul 2024 07:31:16 GMT
Expires: Tue, 23 Jul 2024 07:31:16 GMT
Link: </build/images/icons.15414779.svg>; rel="preload",</bundles/bazingajstranslation/js/translator.min.js?aee7f7cac8e57879>; rel="preload",</js/translations/config.js?95e71d595f9f19b9>; rel="preload",</js/translations/en.js?766e1ac7d71f0aad>; rel="preload",</build/runtime.db876f5c.js>; rel="preload"; as="script",</build/19896.6638e802.js>; rel="preload"; as="script",</build/main.7ec49732.js>; rel="preload"; as="script",</build/fonts/Roboto.630767dc.css>; rel="preload"; as="style",</build/core.8dd1d529.css>; rel="preload"; as="style",</build/themes/jst.664e87bc.css>; rel="preload"; as="style"
Referrer-Policy: same-origin
Server: Caddy
Server: nginx/1.24.0
Vary: Accept-Encoding
Vary: Origin
Vary: Accept-Encoding
Vary: Accept-Language
Vary: Cookie
X-Content-Security-Policy: default-src 'self'; img-src 'self' data: ; script-src 'self' 'unsafe-inline' 'sha256-KiBJHYgQ3JksGRdlBaZEXVQ0UvSiVF+WF0BRuAzJPtg='; style-src 'self' 'unsafe-inline' 'sha256-5djBAhgU6lT6/IvDqBYV1J+3001Gap43QwbVwQ0EoTQ='
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
emma wrote
might wanna add one or two more just to be safe