I also have the same situation with @Lemons and here is what I use for headers:
loginRequest.addHeader("Accept", "text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8");
loginRequest.addHeader("Accept-Encoding", "gzip, deflate, br");
loginRequest.addHeader("Accept-Language", "en-GB,en-US;q=0.8,en;q=0.6");
loginRequest.addHeader("Cache-Control", "max-age=0");
loginRequest.addHeader("Connection", "keep-alive");
loginRequest.addHeader("Content-Type", "application/x-www-form-urlencoded");
loginRequest.addHeader("Host", "secure.runescape.com");
loginRequest.addHeader("Origin", "https://secure.runescape.com");
loginRequest.addHeader("Referer", "https://secure.runescape.com/m=weblogin/loginform.ws?mod=www&ssl=1&expired=0&dest=account_settings.ws");
loginRequest.addHeader("Upgrade-Insecure-Requests", "1");
loginRequest.addHeader("User-Agent", "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36");
This was for login, so you will only need to change the referer link. Credits go to @Explv