Refactoring
request
set  'credentials'  header in cors requests
Refactoring
request
set  'accept' and 'accept-language' headers in all requests
Security
request
explicitly check specified app slug ti  identify a client as a valid 'www' type client