date: |
Wed, 02 Oct 2024 09:26:10 GMT |
content-type: |
text/html; charset=utf-8 |
content-length: |
181402 |
connection: |
close |
vary: |
Accept-Encoding |
set-cookie: |
wcc-hede=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1c2VySWQiOiJTd3V4REtvYnN3UE5LTUNxQk5lNDYiLCJiYXNrZXRLZXkiOiJTd3V4REtvYnN3UE5LTUNxQk5lNDYiLCJ3aXNobGlzdEtleSI6IlN3dXhES29ic3dQTktNQ3FCTmU0NiIsImlhdCI6MTcyNzg2MTE3MH0.nSGYBAkKboMNfMrhyt-QYJaCmkrayJv85eW-g1OZVPk; Max-Age=5184000; Domain=.heine.de; Path=/; Expires=Sun, 01 Dec 2024 09:26:10 GMT; Secure; SameSite=Lax,visitIdChanged=true; Max-Age=1800; Domain=.heine.de; Path=/; Expires=Wed, 02 Oct 2024 09:56:10 GMT; Secure; SameSite=Lax,visitId=hVsyWO9G2CJn3MUmVo-OC; Max-Age=1800; Domain=.heine.de; Path=/; Expires=Wed, 02 Oct 2024 09:56:10 GMT; Secure; SameSite=Lax,ecc=804; Max-Age=2592000; Domain=.heine.de; Path=/; Expires=Fri, 01 Nov 2024 09:26:10 GMT; Secure; SameSite=Lax,eccCurrent=804; Max-Age=2592000; Domain=.heine.de; Path=/; Expires=Fri, 01 Nov 2024 09:26:10 GMT; Secure; SameSite=Lax,eccPaid=804; Max-Age=2592000; Domain=.heine.de; Path=/; Expires=Fri, 01 Nov 2024 09:26:10 GMT; Secure; SameSite=Lax,trigger=impressionen; Max-Age=1800; Domain=.heine.de; Path=/; Expires=Wed, 02 Oct 2024 09:56:10 GMT; Secure; SameSite=Lax,optimizelyId=8N-WsA7dRINgvWMqHHgS5; Max-Age=5184000; Domain=.heine.de; Path=/; Expires=Sun, 01 Dec 2024 09:26:10 GMT; Secure; SameSite=Lax,recoUserId=; Max-Age=0; Domain=.heine.de; Path=/; Expires=Wed, 02 Oct 2024 09:26:10 GMT; Secure; SameSite=Lax,recoSessionId=TXRUkaqFCiCmCKu0eNj4W; Max-Age=604800; Domain=.heine.de; Path=/; Expires=Wed, 09 Oct 2024 09:26:10 GMT; Secure; SameSite=Lax |
content-security-policy: |
default-src 'self' cdn.wcc.heine.de https://cdn.wcc.heine.de/graphql; base-uri 'self'; font-src 'self' cdn.wcc.heine.de https://fonts.gstatic.com data: https://d3dc1lgancj6l0.cloudfront.net https://dq4irj27fs462.cloudfront.net https://*.userwerk.com; img-src * data: https://*.userwerk.com; connect-src 'self' https://cdn.wcc.heine.de/graphql cdn.wcc.heine.de cdn.witt.info/ https://images.ctfassets.net te.heine.de tp.heine.de wasp.heine.de wst.heine.de https://*.analytics.google.com https://*.facebook.com https://*.contentsquare.net https://*.my.onetrust.eu https://*.google-analytics.com https://bat.bing.com eu-witt-gruppe-prod1.mini.snplow.net https://www.google-analytics.com https://www.jsctool.com https://adservice.google.com/pagead/ https://graphql.contentful.com https://privacyportal-eu.onetrust.com https://stats.g.doubleclick.net https://geolocation.onetrust.com https://www.google.com/pagead/ https://googleads.g.doubleclick.net/pagead/ https://*.creativecdn.com https://*.googlesyndication.com https://*.optimizely.com ct.pinterest.com https://jsctool.com checkout-cdn.aboutyou.cloud checkout-v3.wcc.heine.de https://*.ingest.sentry.io wss://chat.userlike.com chat.userlike.com api.userlike.com www.userlike.com https://userlike-cdn-widgets.s3-eu-west-1.amazonaws.com wss://umd.userlike.com/umd/ https://*.userwerk.com https://maps.googleapis.com; object-src 'none'; child-src blob: userlike-cdn-widgets.userlike.com; script-src * 'unsafe-inline' 'unsafe-eval' https://*.adyen.com https://*.paypal.com userlike-cdn-widgets.userlike.com https://*.userwerk.com; style-src 'self' cdn.wcc.heine.de https://www.googletagmanager.com https://fonts.googleapis.com 'unsafe-inline' d.heine.de checkout-cdn.aboutyou.cloud https://*.adyen.com https://*.paypal.com; frame-src 'self' checkout-v3.wcc.heine.de https://*.awin1.com https://*.criteo.net https://*.criteo.com https://*.adrtx.net https://*.contentsquare.net https://www.googletagmanager.com https://www.facebook.com https://www.youtube.com https://dmp.theadex.com https://5127363.fls.doubleclick.net https://12769738.fls.doubleclick.net https://www.jsctool.com https://creativecdn.com/ https://fledge-eu.creativecdn.com/ https://tbs.tradedoubler.com/ https://survey2.quantilope.com/ https://*.adyen.com https://*.paypal.com https://*.computop-paygate.com userlike-cdn-widgets.userlike.com https://*.userwerk.com https://preview.brame-gamification.com/ https://live.brame-gamification.com/; media-src 'self' cdn.wcc.heine.de cdn.witt.info/ https://images.ctfassets.net https://videos.ctfassets.net https://www.youtube.com https://witt-gruppe-res.cloudinary.com https://res.cloudinary.com; manifest-src 'self' cdn.wcc.heine.de; worker-src 'self' cdn.wcc.heine.de blob:; form-action 'self' www.facebook.com https://*.userwerk.com; block-all-mixed-content; frame-ancestors 'self' https://app.contentful.com; sandbox allow-scripts allow-forms allow-same-origin allow-top-navigation allow-popups allow-popups-to-escape-sandbox allow-modals; |
x-dns-prefetch-control: |
off |
x-frame-options: |
SAMEORIGIN |
strict-transport-security: |
max-age=15724800; includeSubDomains |
x-content-type-options: |
nosniff |
referrer-policy: |
strict-origin-when-cross-origin |
x-permitted-cross-domain-policies: |
none |
permissions-policy: |
camera=(), microphone=(), geolocation=() |
x-webapp-version: |
87e37fe65f5708c5c0c341fd156a9b2c17586e62 |
cache-control: |
private, no-cache, no-store, max-age=0, must-revalidate |
etag: |
"o5x6brao6r3vqh" |
server-timing: |
total; dur=168.349278; desc="Total Response Time" |
|