connection: |
close |
content-length: |
151511 |
cache-control: |
max-age=900, public |
content-language: |
de |
content-security-policy: |
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.gbqofs.io *.gbqofs.com *.googleapis.com *.gigya.com *.sessioncam.com *.rewe-static.de *.rewe.de *.krxd.net *.bkrtx.com *.iesnare.com *.googletagmanager.com *.google-analytics.com *.google.com *.google.co.uk *.google.es *.google.de *.google.com.tr *.newrelic.com *.betrad.com bam.nr-data.net static.addtoany.com *.cloudflare.com *.fusepump.com *.youtube.com *.ytimg.com *.evidon.com *.jquery.com *.serving-sys.com *.igodigital.com *.facebook.net *.g.doubleclick.net cdn.hypemarks.com cdn.adimo.co google-analytics.com *.nestle.co.uk *.nestle.de *.gstatic.com *.cloudfront.net *.usabilla.com usabilla.com www.googleadservices.com cdn.cookielaw.org cookie-cdn.cookiepro.com *.onetrust.com https://cdn.gbqofs.com/nestle/nestleprodukttestsde/u/detector-dom.min.js https://www.tintup.com/app/dist/embedded.js https://tintup.com/app/dist/embedded.js; style-src 'self' 'unsafe-inline' *.googleapis.com fonts.gstatic.com https://cdnjs.cloudflare.com brand-ecommerce-assets.fusepump.com *.youtube.com cloud.typography.com *.google.com www.google.com www.google.co.uk *.google.es *.google.de *.google.com.tr cdn.adimo.co *.nestle.de *.cloudfront.net *.usabilla.com usabilla.com https://use.fontawesome.com *.rewe-static.de *.adimo.co; img-src 'self' data: *.googletagmanager.com *.acsitefactory.com *.cloudfront.net *.rewe-static.de *.sessioncam.com *.google.co.in *.adimo.co *.googleapis.com *.gstatic.com *.cloudflare.com *.google-analytics.com *.doubleclick.net www.google.com www.google.co.uk *.google.es *.google.de *.google.com.tr *.betrad.com *.pump.to *.amazonaws.com *.fusepump.com *.evidon.com *.igodigital.com *.facebook.com *.nestle.de bam.nr-data.net *.usabilla.com usabilla.com *.wikimedia.org *.aws.nestle.recipes cdn.cookielaw.org cookie-cdn.cookiepro.com *.onetrust.com https://www.nestle-produkttests.de region1.analytics.google.com; media-src 'self'; frame-src 'self' static.addtoany.com *.youtube.com *.youtu.be youtu.be *.evidon.com *.doubleclick.net *.fusepump.com *.hypemarks.com *.youtube-nocookie.com *.adimo.co *.nestle.de *.nestle.co.uk *.bluekai.com *.shop.rewe-static.de *.google.com www.google.com www.google.co.uk *.google.es *.google.de *.google.com.tr *.cloudfront.net *.usabilla.com usabilla.com *.gigya.com *.sessioncam.com *.bazaarvoice.com *.sitepreview.ws *.krxd.net *.nestle-brands.co.uk *.shopmium.com *.services.nestle-marktplatz.de *.services.nestle-produkttests.de services.nestle-produkttests.de; frame-ancestors 'self' https://staging.services.nestle-produkttests.de/ *.nestle-marktplatz.de *.nestle-produkttests.de *.cocomore.com; child-src 'self' static.addtoany.com *.youtube.com *.youtu.be youtu.be *.evidon.com https://2275258.fls.doubleclick.net http://2275258.fls.doubleclick.net *.nestle.de http://www.youtube-nocookie.com https://www.youtube-nocookie.com https://cdn.hypemarks.com http://cdn.hypemarks.com blob:; font-src 'self' data: *.gbqofs.io *.gbqofs.com *.acsitefactory.com *.rewe-static.de https://cdnjs.cloudflare.com *.nestle.de *.cloudfront.net *.usabilla.com usabilla.com https://use.fontawesome.com cdn.cookielaw.org cookie-cdn.cookiepro.com *.onetrust.com; connect-src 'self' *.gbqofs.io *.gbqofs.com pagead2.googlesyndication.com *.krxd.net *.nr-data.net *.acsitefactory.com *.rewe.de *.rewe-static.de *.sessioncam.com *.fusepump.com *.google-analytics.com https://collect.analyze.ly https://secure-ds.serving-sys.com *.amazonaws.com *.adimo.co *.nestle.de bam.nr-data.net *.evidon.com stats.g.doubleclick.net *.cloudfront.net *.usabilla.com usabilla.com www.google.com googleads.g.doubleclick.net *.bazaarvoice.com cdn.cookielaw.org cookie-cdn.cookiepro.com *.onetrust.com region1.analytics.google.com www.google.de; report-uri /report-csp-violation |
content-type: |
text/html; charset=UTF-8 |
etag: |
W/"1728547400" |
expires: |
Sun, 19 Nov 1978 05:00:00 GMT |
last-modified: |
Thu, 10 Oct 2024 08:03:20 GMT |
server: |
nginx |
strict-transport-security: |
max-age=1000, max-age=300 |
x-content-type-options: |
nosniff |
x-frame-options: |
SAMEORIGIN |
x-pantheon-styx-hostname: |
styx-fe1fe2-c-fcdfb5d99-hh9nd |
x-styx-req-id: |
1d904503-86de-11ef-8218-3208fd4d7f88 |
x-xss-protection: |
1; mode=block |
age: |
518 |
accept-ranges: |
bytes |
via: |
1.1 varnish, 1.1 varnish, 1.1 varnish |
access-control-allow-origin: |
* |
date: |
Thu, 10 Oct 2024 08:11:58 GMT |
x-served-by: |
cache-ams21057-AMS, cache-ams21075-AMS, cache-ams21075-AMS |
x-cache: |
HIT, MISS, MISS |
x-cache-hits: |
0, 0, 0 |
x-timer: |
S1728547919.719030,VS0,VE9 |
vary: |
Accept-Encoding, Cookie, Cookie |