private, max-age=0, no-cache, no-store, must-revalidate
keep-alive
gzip
child-src 'self' https://www.googletagmanager.com https://*.liveperson.net https://cdn.appdynamics.com https://*.lpsnmedia.net https://www.facebook.com https://connect.facebook.net https://*.google.com https://widget.trustpilot.com https://*.doubleclick.net https://www.youtube.com https://static.criteo.net https://*.criteo.com https://wb.messengerpeople.com https://isitetv.com https://*.hotjar.com https://*.akamaihd.net https://*.attn.tv https://*.recaptcha.net https://*.translate.naver.net https://ln-rules.rewardstyle.com https://tr.snapchat.com https://www.shoplooks.com blob:; connect-src 'self' https://*.thcdn.com https://*.ingest.sentry.io https://*.pingdom.net https://*.doubleclick.net https://*.google-analytics.com https://capture.trackjs.com https://fp.zenaps.com https://www.facebook.com https://*.google.com https://*.thehut.net https://privacyportal-eu.onetrust.com https://geolocation.onetrust.com https://cdn.cookielaw.org wss://*.liveperson.net https://ct.pinterest.com https://services.postcodeanywhere.co.uk https://*.akamaihd.net https://*.sciencebehindecommerce.com https://*.googleapis.com https://translate.yandex.net https://*.hotjar.com wss://*.hotjar.com https://*.trustpilot.com https://*.pinterest.com https://*.bing.com https://*.doubleclick.net https://connect.facebook.net https://*.baidu.com https://ampcid.google.com.sg https://tr.snapchat.com https://privacyportal-eu.onetrust.com https://*.contentsquare.net https://*.criteo.com data: https://*.prod.mplat-ppcprotect.com https://*.lunio.ai; font-src 'self' data: https://*.thcdn.com https://fp.zenaps.com https://cdnjs.cloudflare.com https://fonts.gstatic.com https://fonts.googleapis.com https://static.thgcdn.cn; form-action 'self' https://www.facebook.com https://www.lookfantastic.com.sg https://m.lookfantastic.com.sg https://checkout.lookfantastic.com.sg https://connect.facebook.net https://www.glossybox.at https://www.glossybox.ch https://www.glossybox.co.uk https://www.glossybox.com https://www.glossybox.de https://www.glossybox.fi https://www.glossybox.fr https://www.glossybox.ie https://www.glossybox.no https://www.glossybox.se https://www.glossybox.dk https://tr.snapchat.com; img-src 'self' data: https://*.thcdn.com https://col.eum-appdynamics.com https://usage.trackjs.com https://*.lpsnmedia.net https://*.doubleclick.net https://www.google-analytics.com https://*.google.com https://cx.atdmt.com https://www.zenaps.com https:; media-src 'self' https://*.thcdn.com https://*.lpsnmedia.net https://static.thgcdn.cn; object-src 'self' https://*.thcdn.com https://www.youtube.com; report-uri https://csp.thehut.net/cspReport.txt; script-src 'self' 'unsafe-eval' 'unsafe-inline' data: https://*.thcdn.com https://*.thehut.net https://rum-static.pingdom.net https://*.liveperson.net https://*.lpsnmedia.net https://*.doubleclick.net https://static.cdn-apple.com https://*.liveperson.com https://geolocation.onetrust.com https://cdn.cookielaw.org https://google.com https://www.googletagmanager.com https://cdnjs.cloudflare.com https://fp.zenaps.com https://www.youtube.com https://www.google-analytics.com https://*.google.com https://connect.facebook.net https://bat.bing.com https://widget.trustpilot.com https://s.ytimg.com https://www.googletagservices.com https://*.googleapis.com https://www.facebook.com https://www.googleadservices.com https://www.gstatic.com https://www.dwin1.com https://cdn.trackjs.com https://seal.digicert.com https://static.criteo.net https://*.criteo.com https://*.recaptcha.net https://*.sciencebehindecommerce.com https://*.microsofttranslator.com https://*.hotjar.com https://*.akamaihd.net https://*.attn.tv https://*.trustpilot.com https://*.translate.naver.net https://*.bing.com https://*.doubleclick.net https://ln-rules.rewardstyle.com https://*.google-analytics.com https://static.ads-twitter.com https://*.baidu.com https://sc-static.net https://*.google.co.uk https://google.co.uk https://*.shoplooks.com https://slooks.top https://slooks.me https://lantern.roeyecdn.com https://lantern.roeye.com https://static.thgcdn.cn https://*.googlesyndication.com https://geolocation.onetrust.com https://*.contentsquare.net https://app.contentsquare.com; style-src 'self' 'unsafe-inline' https://*.thcdn.com https://*.google.com https://*.googleapis.com https://fp.zenaps.com https://cdnjs.cloudflare.com https://www.googletagmanager.com https://*.googleapis.com https://*.translate.naver.net https://*.microsofttranslator.com https://www.shoplooks.com https://static.shoplooks.com https://static.thgcdn.cn; upgrade-insecure-requests; report-to report-endpoint
text/html;charset=UTF-8
Wed, 10 Jan 2024 10:52:02 GMT
Thu, 01 Jan 1970 00:00:00 GMT
timeout=60
no-cache
unsafe-url
{"group":"report-endpoint","max_age":86400,"endpoints":[{"url":"https://csp.thehut.net/cspReport.txt","priority":1,"weight":1}],"include_subdomains":true}
JSESSIONID=E7C93EC5FB621F4FF6614E0272FE90ED; Path=/; Secure; HttpOnly, locale_V6=en_SG; Version=1; Domain=.lookfantastic.com.sg; Path=/; Max-Age=31556926; Expires=Thu, 09-Jan-2025 16:40:48 GMT; SameSite=None; Secure, csrf_token=65403974000315762928; Version=1; Path=/; SameSite=None; HttpOnly; Secure, NSC_mc_wtsw_efgbvmu_xfctsw_8010_H=5508a3d3e1c926c22b41cc049e8f4ead4cdd27798bba0cca9c4ba99a13226349b742f442;expires=Wed, 10-Jan-2024 13:52:02 GMT;path=/;secure;httponly
max-age=31536000; includeSubDomains; preload
chunked
nosniff
SAMEORIGIN
1; mode=block; report=/xssProtection.txt
accept-encoding
|