bytes
no-store, no-cache, must-revalidate, max-age=0
keep-alive
gzip
48754
font-src *.gstatic.com data: script.hotjar.com static.lipscore.com *.klarnacdn.net 'self' data: *.hotjar.com *.hotjar.io *.zmags.com *.googleapis.com *.europris.no 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com facebook.com *.facebook.com *.facebook.net *.snapchat.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googletagmanager.com *.youtube.com *.klarna.com big.g.doubleclick.net vars.hotjar.com optimize.google.com *.charpstar.net *.google.com *.adsrvr.org *.snapchat.com *.facebook.com *.jsdelivr.net *.hotjar.com *.europris.no player.vimeo.com *.hotjar.io *.zmags.com candidate.hr-manager.net tpc.googlesyndication.com *.doubleclick.net europris.leadfamly.com static.itxuc.com policy.app.cookieinformation.com europris.campaign.playable.com www.linkedin.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: *.vimeocdn.com *.google.com *.google.no *.google.se *.google.fi *.google.ro *.google.pl *.google.dk *.gstatic.com *.google-analytics.com *.googleadservices.com googleads.g.doubleclick.net *.klarna.com *.klarnaevt.com *.hotjar.com *.hotjar.io *.googletagmanager.com static.lipscore.com blob: img.youtube.com *.klarnacdn.net *.klarnaservices.com 'self' data: charpstar.se i.ytimg.com *.googleapis.com *.zmags.com *.europris.no *.google.lt *.google.sk *.google.ie *.google.es *.google.nl *.google.fr *.doubleclick.net *.facebook.com *.facebook.net ep-campaign-images.temalogic.com gen.sendtric.com *.googlesyndication.com gtm-w4pzjrn-njm2m.uc.r.appspot.com *.bing.com *.streamify.io *.clarity.ms *.linkedin.com *.licdn.com *.ads.licdn.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googletagmanager.com jquery.sellxed.com *.google.com *.gstatic.com *.google-analytics.com *.googleanalytics.com *.googleadservices.com *.googleoptimize.com *.doubleclick.net *.klarna.com static.hotjar.com script.hotjar.io static.lipscore.com *.klarnacdn.net *.klarnaservices.com *.charpstar.net *.googleapis.com *.zmags.com c.z-analytics.net *.googletagmanager.com *.hotjar.com *.hotjar.io *.facebook.net *.jsdelivr.net *.adsrvr.org sc-static.net *.adform.net *.europris.no *.googlesyndication.com services.itxuc.com policy.app.cookieinformation.com gtm-w4pzjrn-njm2m.uc.r.appspot.com *.bing.com *.clarity.ms *.zma.gs *.streamify.io *.snapchat.com *.lunio.ai demoapp-api.bloomreach.com api-engagement.bloomreach.com api.exponea.com api.eu1.exponea.com europris.campaign.playable.com cdn-engagement.bloomreach.com snap.licdn.com static-exp1.licdn.com content.linkedin.com platform.linkedin.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.gstatic.com *.googleapis.com *.google.com static.lipscore.com *.klarnacdn.net *.zmags.com *.europris.no *.googletagmanager.com gtm-w4pzjrn-njm2m.uc.r.appspot.com *.streamify.io *.zma.gs *.licdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src data: *.streamify.io blob: media.linkedin.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com *.doubleclick.net *.klarna.com *.klarnaevt.com *.hotjar.com vc.hotjar.io surveystats.hotjar.io wss://*.hotjar.com *.google.com *.googleapis.com t.elasticsuite.io wapi.lipscore.com users.lipscore.com https://app.getsentry.com *.klarnaservices.com *.charpstar.net europris.ingest.z-analytics.net *.zmags.com *.hotjar.io *.europris.no *.facebook.com *.lunio.ai *.snapchat.com *.googlesyndication.com *.cookieinformation.com *.clarity.ms *.streamify.io wss://*.streamify.io *.zma.gs *.googletagmanager.com no-europris-saas1.collector.snplow.net demoapp-api.bloomreach.com api-engagement.bloomreach.com api.exponea.com api.eu1.exponea.com europris.campaign.playable.com cdn-engagement.bloomreach.com *.linkedin.com *.licdn.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://eng.vdc.dev/csp-report; report-to report-endpoint;
text/html; charset=UTF-8
Fri, 12 Jan 2024 18:35:22 GMT
-1
no-cache
{"group":"report-endpoint","max_age":10886400,"endpoints":[{"url":"https:\/\/eng.vdc.dev\/csp-report"}]}
Accept-Encoding,Origin
nosniff
SAMEORIGIN, SAMEORIGIN
base
app6
IE=edge
1; mode=block
|