date: |
Thu, 03 Oct 2024 00:44:37 GMT |
content-type: |
text/html;charset=UTF-8 |
transfer-encoding: |
chunked |
connection: |
close |
server: |
nginx |
vary: |
Accept-Encoding |
x-content-type-options: |
nosniff |
x-frame-options: |
SAMEORIGIN |
x-xss-protection: |
1 |
set-cookie: |
JSESSIONID=A250D04891B8730AC55868FFD893D236; Path=/; Secure; HttpOnly; SameSite=None,COOKIE_SUPPORT=true; Max-Age=31536000; Expires=Fri, 03 Oct 2025 00:44:37 GMT; Path=/; HttpOnly; SameSite=None; Secure,GUEST_LANGUAGE_ID=de_DE; Max-Age=31536000; Expires=Fri, 03 Oct 2025 00:44:37 GMT; Path=/; HttpOnly; SameSite=None; Secure,INGRESSCOOKIE=b67a74c7b60bc8c7|Zv3o+; path=/; HttpOnly; Secure; SameSite=None |
expires: |
Thu, 01 Jan 1970 00:00:00 GMT |
cache-control: |
private, no-cache, no-store, must-revalidate |
pragma: |
no-cache |
correlation-context: |
servicegraph_target_service=liferay |
content-security-policy: |
default-src 'self' 'unsafe-inline' dbs.degussa-bank.de api.dbs.degussa-bank.de saofccdnprodttsxasv1wfmo.blob.core.windows.net dc.services.visualstudio.com *.luware.cloud *.service.signalr.net wss://*.service.signalr.net ecs.office.com browser.events.data.microsoft.com *.skype.com wss://*.skype.com *.teams.microsoft.com ofc-cdn.azureedge.net ecs.communication.microsoft.com wss://*.trouter.teams.microsoft.com *.events.data.microsoft.com go-eu.trouter.communication.microsoft.com business-customer.vwd.com *.doubleclick.net www.google.de www.google.com *.googleapis.com *.google-analytics.com *.gstatic.com www.googletagmanager.com *.analytics.google.com *.usercentrics.eu chat600.realperson.de webid-gateway.de api.ahoyrtc.com;connect-src 'self' dbs.degussa-bank.de api.dbs.degussa-bank.de saofccdnprodttsxasv1wfmo.blob.core.windows.net dc.services.visualstudio.com *.luware.cloud *.service.signalr.net wss://*.service.signalr.net ecs.office.com browser.events.data.microsoft.com *.skype.com wss://*.skype.com *.teams.microsoft.com ofc-cdn.azureedge.net ecs.communication.microsoft.com wss://*.trouter.teams.microsoft.com *.events.data.microsoft.com go-eu.trouter.communication.microsoft.com business-customer.vwd.com webid-gateway.de api.ahoyrtc.com *.usercentrics.eu wss://*.degussa-bank.de wss://*.liferay.prod.aws.degbank.local www.google.de www.google.com *.googleapis.com *.google-analytics.com *.gstatic.com www.googletagmanager.com *.analytics.google.com *.doubleclick.net;script-src 'self' 'unsafe-inline' 'unsafe-eval' dbs.degussa-bank.de api.dbs.degussa-bank.de saofccdnprodttsxasv1wfmo.blob.core.windows.net dc.services.visualstudio.com *.luware.cloud *.service.signalr.net wss://*.service.signalr.net ecs.office.com browser.events.data.microsoft.com *.skype.com wss://*.skype.com *.teams.microsoft.com ofc-cdn.azureedge.net ecs.communication.microsoft.com wss://*.trouter.teams.microsoft.com *.events.data.microsoft.com go-eu.trouter.communication.microsoft.com business-customer.vwd.com webid-gateway.de api.ahoyrtc.com chat600.realperson.de *.usercentrics.eu www.google.de www.google.com *.googleapis.com *.google-analytics.com *.gstatic.com www.googletagmanager.com *.analytics.google.com;frame-src 'self' outlook.office365.com *.vimeo.com www.mr-money.de www.youtube.com *.usercentrics.eu degussapublic.factsheetslive.com;frame-ancestors 'self' *.degussa-bank.de *.liferay.prod.aws.degbank.local www.heim-und-immobilie.de *.mitarbeitervorteile.de intranet.indego.de intranet.degbank.local *.prodyna.com *.check24.de liferay-develop-iframe-test.s3.eu-central-1.amazonaws.com;img-src 'self' blob: data: dbs.degussa-bank.de api.dbs.degussa-bank.de saofccdnprodttsxasv1wfmo.blob.core.windows.net dc.services.visualstudio.com *.luware.cloud *.service.signalr.net wss://*.service.signalr.net ecs.office.com browser.events.data.microsoft.com *.skype.com wss://*.skype.com *.teams.microsoft.com ofc-cdn.azureedge.net ecs.communication.microsoft.com wss://*.trouter.teams.microsoft.com *.events.data.microsoft.com go-eu.trouter.communication.microsoft.com www.google.de www.google.com *.googleapis.com *.google-analytics.com *.gstatic.com www.googletagmanager.com *.analytics.google.com *.usercentrics.eu;worker-src blob: |
strict-transport-security: |
max-age=31536000; includeSubDomains; preload |