Resta saysResponse headers describe the result: content type, caching rules, CORS, and cookies.
The server answers with headers too. Content-Type tells you the body's format; Cache-Control/ETag govern caching; Set-Cookie stores session data; Access-Control-Allow-Origin handles CORS; Location points at a created/redirected resource. Reading these is how clients behave correctly without guessing.
Power-ups you unlock
Content-Type: body format
Cache-Control/ETag: caching rules
Set-Cookie: session storage
Access-Control-Allow-Origin: CORS
The 401 Bandit attacks — common mistakes
Ignoring Content-Type and mis-parsing the body
Overlooking caching headers (stale or no caching)
Missing CORS headers and blaming the client
Boss battleName the response header that enables cross-origin browser access.