Content-Type, Authorization
GET,POST
max-age=0
Keep-Alive
default-src 'self' data:; script-src 'self' 'unsafe-inline' 'unsafe-eval' widget.gleamjs.io www.paypal.com https://tenantpluginapiserver1.voice.cc.conpeek.com www.paypalobjects.com platform.instagram.com www.instagram.com *.vimeo.com *.vimeocdn.com *.newrelic.com *.nr-data.net www.googletagservices.com *.googlesyndication.com *.googleadservices.com googleads.g.doubleclick.net adservice.google.com adservice.google.ae adservice.google.al adservice.google.at adservice.google.be adservice.google.bg adservice.google.bs adservice.google.ca adservice.google.ch adservice.google.ci adservice.google.cl adservice.google.co.bw adservice.google.co.cr adservice.google.co.id adservice.google.co.il adservice.google.co.in adservice.google.co.jp adservice.google.co.ke adservice.google.co.kr adservice.google.co.mz adservice.google.co.nz adservice.google.co.th adservice.google.co.tz adservice.google.co.uk adservice.google.co.uz adservice.google.co.ve adservice.google.co.za adservice.google.co.zm adservice.google.co.zw adservice.google.com.ai adservice.google.com.ar adservice.google.com.au adservice.google.com.bd adservice.google.com.bh adservice.google.com.bn adservice.google.com.bo adservice.google.com.br adservice.google.com.co adservice.google.com.cy adservice.google.com.ec adservice.google.com.eg adservice.google.com.et adservice.google.com.fj adservice.google.com.gh adservice.google.com.gi adservice.google.com.gt adservice.google.com.hk adservice.google.com.jm adservice.google.com.kh adservice.google.com.kw adservice.google.com.lb adservice.google.com.mm adservice.google.com.mt adservice.google.com.mx adservice.google.com.my adservice.google.com.ng adservice.google.com.ni adservice.google.com.np adservice.google.com.om adservice.google.com.pa adservice.google.com.pe adservice.google.com.ph adservice.google.com.pk adservice.google.com.pr adservice.google.com.py adservice.google.com.qa adservice.google.com.sa adservice.google.com.sg adservice.google.com.sv adservice.google.com.tr adservice.google.com.tw adservice.google.com.ua adservice.google.com.uy adservice.google.com.vn adservice.google.cz adservice.google.de adservice.google.dk adservice.google.dz adservice.google.ee adservice.google.es adservice.google.fi adservice.google.fr adservice.google.ge adservice.google.gr adservice.google.gy adservice.google.hn adservice.google.pl adservice.google.hu adservice.google.ie adservice.google.im adservice.google.iq adservice.google.is adservice.google.it adservice.google.jo adservice.google.kz adservice.google.li adservice.google.lk adservice.google.lt adservice.google.lu adservice.google.lv adservice.google.md adservice.google.mk adservice.google.mu adservice.google.nl adservice.google.no adservice.google.pl adservice.google.pt adservice.google.ro adservice.google.rs adservice.google.ru adservice.google.se adservice.google.si adservice.google.sk adservice.google.so adservice.google.sr adservice.google.tl adservice.google.tn adservice.google.tt google-analytics.com www.google-analytics.com ssl.google-analytics.com stats.g.doubleclick.net ajax.googleapis.com maps.googleapis.com maps.google.com translate.googleapis.com translate.google.com www.googletagmanager.com googletagmanager.com tagmanager.google.com *.cloudflare.com *.jquery.com *.googleapis.com *.google-analytics.com www.google.com www.googletagmanager.com *.googletagmanager.com tagmanager.google.com www.gstatic.com *.facebook.net *.clarity.ms *.erecruiter.pl; style-src 'self' 'unsafe-inline' data: *.vimeocdn.com fonts.googleapis.com hello.myfonts.net 'unsafe-inline' https://tenantpluginapiserver1.voice.cc.conpeek.com maps.googleapis.com maps.google.com translate.googleapis.com www.googletagmanager.com *.googletagmanager.com tagmanager.google.com gstatic.com *.gstatic.com *.erecruiter.pl; img-src 'self' data: s.w.org ps.w.org ts.w.org secure.gravatar.com www.gravatar.com *.gleam.io data: www.paypalobjects.com *.paypal.com c.tile.openstreetmap.org a.tile.openstreetmap.org b.tile.openstreetmap.org .googlesyndication.com stats.g.doubleclick.net blob: google-analytics.com www.google-analytics.com ssl.google-analytics.com www.google.com *.googleapis.com maps.google.com maps.gstatic.com www.gstatic.com *.ggpht.com translate.googleapis.com translate.google.com i.ytimg.com www.googletagmanager.com *.google.com google.com *.google.hu google.hu *.google.pl google.pl *.facebook.com facebook.com www.facebook.com *.clarity.ms *.bing.com; connect-src 'self' www.paypalobjects.com *.paypal.com *.vimeo.com *.googlesyndication.com googleads.g.doubleclick.net stats.g.doubleclick.net www.google-analytics.com ampcid.google.com analytics.google.com about: maps.googleapis.com maps.google.com translate.googleapis.com www.googletagmanager.com *.analytics.google.com *.google-analytics.com stats.g.doubleclick.net google-analytics.com *.google.hu google.com *.google.com *.google.pl *.clarity.ms yoast.com; font-src 'self' data: data: fonts.gstatic.com fonts.googleapis.com; frame-src 'self' data: gleam.io www.paypalobjects.com *.paypal.com https://tenantpluginapiserver1.voice.cc.conpeek.com www.instagram.com *.vimeo.com *.vimeocdn.com *.googlesyndication.com googleads.g.doubleclick.net maps.googleapis.com maps.google.com www.youtube.com www.googletagmanager.com *.googletagmanager.com tagmanager.google.com www.google.com google.com *.google.com webbooking-pl.affidea.com td.doubleclick.net; child-src 'self' www.paypalobjects.com *.paypal.com *.vimeo.com *.vimeocdn.com www.youtube.com www.googletagmanager.com blob: affidea.pl affidea.com *.affidea.com; block-all-mixed-content; frame-ancestors 'self'; worker-src blob: affidea.pl;, upgrade-insecure-requests;
text/html; charset=UTF-8
unsafe-none; report-to='default'
unsafe-none; report-to='default'
unsafe-none
unsafe-none; report-to='default'
cross-origin
Tue, 10 Mar 2026 07:45:12 GMT
Tue, 10 Mar 2026 07:45:12 GMT
timeout=5, max=100
Tue, 10 Mar 2026 02:19:30 GMT
accelerometer=(), autoplay=(), camera=(), cross-origin-isolated=(), display-capture=(self), encrypted-media=(), fullscreen=*, geolocation=(self), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), payment=*, picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=(), xr-spatial-tracking=(), gamepad=(), serial=()
strict-origin-when-cross-origin
Apache/2.4.65
cookiesession1=678A3E21E668AE34F93298C5D5BECA21;Expires=Wed, 10 Mar 2027 07:47:16 GMT;Path=/;Secure;HttpOnly
max-age=31536000; includeSubDomains
Accept-Encoding
default-src 'self'; img-src *; media-src * data:;
nosniff
SAMEORIGIN, SAMEORIGIN
none
1; mode=block
|