HTTP/1.1 302 Found
Date: Thu, 03 Mar 2022 09:39:47 GMT
Content-Type: text/html; charset=UTF-8
Set-Cookie: PHPSESSID=nefie4nf90qsooucl0t0kth7bt; expires=Thu, 03-Mar-2022 10:39:46 GMT; Max-Age=3600; path=/; domain=topromobility.ch; HttpOnly
Location: https://www.topromobility.ch/
Report-To: {"group":"report-endpoint","max_age":10886400,"endpoints":[{"url":"https:\/\/eng.vdc.dev\/csp-report"}]}
Content-Security-Policy: worker-src blob:; font-src *.gstatic.com 'self' data: data: script.hotjar.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.google.com *.youtube.com *.klarna.com big.g.doubleclick.net vars.hotjar.com *.facebook.com *.netigate.se *.adobe.com *.adyen.com *.involve.me *.doubleclick.net 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com 'self' data: *.google.com *.google.bg *.facebook.com data: *.google.no *.google.se *.google.fi *.google.ro *.google.pl *.google.dk *.gstatic.com *.google-analytics.com *.googleadservices.com googleads.g.doubleclick.net *.klarna.com *.klarnaevt.com *.hotjar.com *.hotjar.io topro.wpcloud.trollweb.no www.facebook.com cx.atdmt.com *.adyen.com *.hsforms.com *.hubspot.com *.klarnacdn.net blob: *.google.lt *.google.at *.google.co.uk *.google.ch *.google.de *.google.nl *.google.fr *.google.com.au *.google.com.ua *.ytimg.com *.instagram.com *.omtrdc.net *.googletagmanager.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com js.authorize.net jstest.authorize.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com js.braintreegateway.com s.ytimg.com video.google.com vimeo.com www.vimeo.com cdn-scripts.signifyd.com www.youtube.com polyfill.io *.google.com *.googletagmanager.com *.facebook.net *.doubleclick.net *.gstatic.com *.google-analytics.com *.googleadservices.com *.klarna.com static.hotjar.com script.hotjar.io storage.googleapis.com *.adyen.com *.involve.me *.hs-scripts.com *.hs-analytics.net *.hscollectedforms.net *.hs-banner.com script.hotjar.com *.klarnacdn.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.googleapis.com *.gstatic.com tagmanager.google.com topro.wpcloud.trollweb.no storage.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src data: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.algolia.net *.google-analytics.com *.doubleclick.net *.klarna.com *.klarnaevt.com *.hotjar.com vc.hotjar.io surveystats.hotjar.io wss://*.hotjar.com storage.googleapis.com *.mapbox.com *.facebook.com *.google.com *.google.at *.google.com.ua *.google.com.au *.google.no *.google.de *.google.co.uk *.google.lt *.google.fr *.google.ch *.google.nl *.hubspot.com *.hs-banner.com *.demdex.net 'self' 'unsafe-inline'; child-src blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://eng.vdc.dev/csp-report; report-to report-endpoint;
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
Access-Control-Allow-Origin: *
Content-Encoding: gzip
Vary: Accept-Encoding
Pragma: no-cache
Expires: -1
Cache-Control: no-store, no-cache, must-revalidate, max-age=0
Connection: keep-alive
HTTP/2 200
server: nginx/1.14.0 (Ubuntu)
date: Thu, 03 Mar 2022 09:39:47 GMT
content-type: text/html; charset=UTF-8
vary: Accept-Encoding
report-to: {"group":"report-endpoint","max_age":10886400,"endpoints":[{"url":"https:\/\/eng.vdc.dev\/csp-report"}]}
content-security-policy: worker-src blob:; font-src *.gstatic.com 'self' data: data: script.hotjar.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.google.com *.youtube.com *.klarna.com big.g.doubleclick.net vars.hotjar.com *.facebook.com *.netigate.se *.adobe.com *.adyen.com *.involve.me *.doubleclick.net 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com 'self' data: *.google.com *.google.bg *.facebook.com data: *.google.no *.google.se *.google.fi *.google.ro *.google.pl *.google.dk *.gstatic.com *.google-analytics.com *.googleadservices.com googleads.g.doubleclick.net *.klarna.com *.klarnaevt.com *.hotjar.com *.hotjar.io topro.wpcloud.trollweb.no www.facebook.com cx.atdmt.com *.adyen.com *.hsforms.com *.hubspot.com *.klarnacdn.net blob: *.google.lt *.google.at *.google.co.uk *.google.ch *.google.de *.google.nl *.google.fr *.google.com.au *.google.com.ua *.ytimg.com *.instagram.com *.omtrdc.net *.googletagmanager.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com js.authorize.net jstest.authorize.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com js.braintreegateway.com s.ytimg.com video.google.com vimeo.com www.vimeo.com cdn-scripts.signifyd.com www.youtube.com polyfill.io *.google.com *.googletagmanager.com *.facebook.net *.doubleclick.net *.gstatic.com *.google-analytics.com *.googleadservices.com *.klarna.com static.hotjar.com script.hotjar.io storage.googleapis.com *.adyen.com *.involve.me *.hs-scripts.com *.hs-analytics.net *.hscollectedforms.net *.hs-banner.com script.hotjar.com *.klarnacdn.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.googleapis.com *.gstatic.com tagmanager.google.com topro.wpcloud.trollweb.no storage.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src data: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.algolia.net *.google-analytics.com *.doubleclick.net *.klarna.com *.klarnaevt.com *.hotjar.com vc.hotjar.io surveystats.hotjar.io wss://*.hotjar.com storage.googleapis.com *.mapbox.com *.facebook.com *.google.com *.google.at *.google.com.ua *.google.com.au *.google.no *.google.de *.google.co.uk *.google.lt *.google.fr *.google.ch *.google.nl *.hubspot.com *.hs-banner.com *.demdex.net 'self' 'unsafe-inline'; child-src blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://eng.vdc.dev/csp-report; report-to report-endpoint;
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
x-frame-options: SAMEORIGIN
access-control-allow-origin: *
pragma: no-cache
expires: -1
cache-control: no-store, no-cache, must-revalidate, max-age=0
accept-ranges: bytes
access-control-allow-origin: *
|