true
Access-Control-Allow-Headers,Access-Control-Allow-Methods,Access-Control-Allow-Origin,Access-Control-Max-Age,Content-Type,Content-Length,Date,Cache-Control,Expires,Etag,Strict-Transport-Security,Content-Security-Policy,Cross-Origin-Opener-Policy,Cross-Origin-Embedder-Policy,X-Content-Type-Options,X-Permitted-Cross-Domain-Policies,Permissions-Policy,Referrer-Policy,Vary,Accept-Ranges,X-Frame-Options
GET,POST,PUT,DELETE,OPTIONS,PATCH
www.google-analytics.com
600
max-age=1200
keep-alive
gzip
default-src 'self'; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' *.usercentrics.eu *.luigisbox.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.google.com *.google.de cdn.jsdelivr.net *.online-metrix.net *.trbo.com *.unzer.com cdnjs.cloudflare.com paypalobjects.com *.magnolia-platform.com bat.bing.com googleads.g.doubleclick.net *.kameleoon.io *.kameleoon.com *.kameleoon.eu *.visualwebsiteoptimizer.com blob: d2bgdldl6xit7z.cloudfront.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.usercentrics.eu *.luigisbox.com *.google-analytics.com *.googletagmanager.com cdn.jsdelivr.net *.trbo.com *.unzer.com cdnjs.cloudflare.com paypalobjects.com *.kameleoon.io *.kameleoon.com *.kameleoon.eu *.visualwebsiteoptimizer.com blob:; object-src 'self' blob:; style-src 'self' *.luigisbox.com 'unsafe-inline' *.magnolia-platform.com d2bgdldl6xit7z.cloudfront.net; base-uri 'self'; connect-src 'self' *.luigisbox.com *.usercentrics.eu *.kameleoon.com *.google.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net api.phrase.com d2bgdldl6xit7z.cloudfront.net blob: *.unzer.com *.magnolia-platform.com data.kameleoon.io *.kik.de *.kik.at *.kik.pl *.trbo.com *.visualwebsiteoptimizer.com; font-src 'self' data: fonts.googleapis.com fonts.gstatic.com *.magnolia-platform.com; frame-src 'self' *.usercentrics.eu *.trbo.com *.unzer.com; frame-ancestors 'self' *.magnolia-platform.com; img-src 'self' data: *.usercentrics.eu *.luigisbox.com *.kameleoon.com *.kik.de *.kik.at *.kik.pl *.trbo.com *.unzer.com www.google-analytics.com www.googletagmanager.com googleads.g.doubleclick.net *.magnolia-platform.com *.wt-eu02.net bat.bing.com www.google.com www.google.de *.visualwebsiteoptimizer.com static.phrase.com; manifest-src 'self'; media-src 'self'; worker-src 'self' blob:
text/html; charset=utf-8
unsafe-none
same-origin
Wed, 10 Jan 2024 12:22:17 GMT
"d6dae-00A/dO7RryK+OXlIzlYF+hVJo+U"
Wed, 10 Jan 2024 12:27:42 GMT
geolocation=(self), midi=(self), notifications=(self), push=(self), sync-xhr=(), microphone=(self), camera=(self), magnetometer=(self), gyroscope=(self), speaker=(self), vibrate=(self), fullscreen=(self), payment=(self)
strict-origin-when-cross-origin
myracloud
max-age=31536000; includeSubDomains; preload
user-agent, accept-encoding
1
nosniff
none
|