identity,gzip
no-cache, no-store
gzip
base-uri 'self' ; child-src https://www.dropbox.com/static/serviceworker/ blob: ; connect-src https://* ws://127.0.0.1:*/ws wss://dsimports.dropbox.com/ ; default-src 'none' ; font-src https://* data: ; form-action 'self' https://www.dropbox.com/ https://dl-web.dropbox.com/ https://photos.dropbox.com/ https://paper.dropbox.com/ https://showcase.dropbox.com/ https://www.hellofax.com/ https://app.hellofax.com/ https://www.hellosign.com/ https://app.hellosign.com/ https://docsend.com/ https://www.docsend.com/ https://help.dropbox.com/ https://navi.dropbox.jp/ https://a.sprig.com/ https://selfguidedlearning.dropboxbusiness.com/ https://instructorledlearning.dropboxbusiness.com/ https://sales.dropboxbusiness.com/ https://accounts.google.com/ https://api.login.yahoo.com/ https://login.yahoo.com/ https://experience.dropbox.com/ https://pal-test.adyen.com https://2e83413d8036243b-Dropbox-pal-live.adyenpayments.com/ https://onedrive.live.com/picker ; frame-src https://* carousel: dbapi-6: dbapi-7: dbapi-8: dropbox-client: itms-apps: itms-appss: ; img-src https://* data: blob: ; media-src https://* blob: ; object-src 'self' https://cfl.dropboxstatic.com/static/ https://www.dropboxstatic.com/static/ ; report-uri https://www.dropbox.com/csp_log?policy_name=metaserver-whitelist ; script-src 'unsafe-eval' https://www.dropbox.com/static/api/ https://www.dropbox.com/page_success/ https://cfl.dropboxstatic.com/static/ https://www.dropboxstatic.com/static/ https://accounts.google.com/gsi/client https://canny.io/sdk.js 'nonce-vM7zOWtM5cDR8VgJ2zh1' ; style-src https://* 'unsafe-inline' 'unsafe-eval' ; worker-src https://www.dropbox.com/static/serviceworker/ https://www.dropbox.com/encrypted_folder_download/service_worker.js blob:, report-uri https://www.dropbox.com/csp_log?policy_name=metaserver-dynamic ; script-src 'unsafe-eval' 'strict-dynamic' 'nonce-vM7zOWtM5cDR8VgJ2zh1' 'nonce-/cZay/leMM2wdmbb+xO6'
application/json
Wed, 10 Jan 2024 17:12:57 GMT
strict-origin-when-cross-origin
envoy
gvc=MjM2MjgzOTQxNjIyMzM2OTA1NTU5NzIxMzc3NDk3Nzk1MzI3Njcy; expires=Mon, 08 Jan 2029 17:12:58 GMT; HttpOnly; Path=/; SameSite=None; Secure, t=rJPEHIGEZWGO3Mtlg8CceNDS; Domain=dropbox.com; expires=Sat, 09 Jan 2027 17:12:57 GMT; HttpOnly; Path=/; SameSite=None; Secure, __Host-js_csrf=rJPEHIGEZWGO3Mtlg8CceNDS; expires=Sat, 09 Jan 2027 17:12:57 GMT; Path=/; SameSite=None; Secure, __Host-ss=vEE_H4kJ_4; expires=Sat, 09 Jan 2027 17:12:57 GMT; HttpOnly; Path=/; SameSite=Strict; Secure, locale=ja; Domain=dropbox.com; expires=Mon, 08 Jan 2029 17:12:58 GMT; Path=/; SameSite=None; Secure
max-age=31536000; includeSubDomains, max-age=31536000; includeSubDomains
chunked
Accept-Encoding
nosniff
bf74a59101ad42c59d9061431e0354b1
far_remote
DENY
none
1; mode=block
|