HTTP Security Headers
battlenet.com.cn
Final status: 401
http://battlenet.com.cn (308)https://battlenet.com.cn/ (302)https://shop.battlenet.com.cn/ (302)https://shop.battlenet.com.cn/oauth2/authorization/storefront?ref=http://shop.battlenet.com.cn/&optLogin=true (302)https://oauth.battlenet.com.cn/authorize?response_type=code&client_id=a1645ac274514d8ebe9b5ffab1a30660&scope=account.basic%20account.full%20openid%20web.storefront%20web.storefront.internal%20web.storefront.internal:modify%20commerce.wishlist%20commerce.wishlist:modify%20commerce.wishlist.internal%20web.storefront.internal:bypass-product-scheduling%20commerce.catalog.availability:override&state=nPsYb0CNB9mpN345-h3mwQn0RHjV1KByNIO9jLVe5is%3D&redirect_uri=https://shop.battlenet.com.cn/login/oauth2/code/storefront&nonce=Um89mBDfk7itJ2uxuH_fXYmhXqUbHk96rs-3Ciiegl0&optLogin=true (302)https://shop.battlenet.com.cn/login/oauth2/code/storefront#optLogin=true (401)
Security Headers
Strict-Transport-Security (HSTS)
Forces browsers to use HTTPS, preventing protocol-downgrade attacks.
Content-Security-Policy (CSP)
Limits where scripts/resources can load from — the strongest defense against XSS.
X-Frame-Options — missing
Blocks the site from being embedded in iframes (clickjacking protection).
X-Content-Type-Options
Stops browsers from MIME-sniffing responses away from the declared type.
Referrer-Policy no-referrer-when-downgrade
Controls how much referrer information is sent to other sites.
Permissions-Policy — missing
Restricts access to browser features like camera, microphone, geolocation.