server: |
nginx |
date: |
Mon, 30 Sep 2024 01:08:12 GMT |
content-type: |
text/html; charset=UTF-8 |
transfer-encoding: |
chunked |
connection: |
close |
vary: |
Accept-Encoding |
set-cookie: |
PHPSESSID=ubeiupcoib0890g5fllhjbrlj2; expires=Mon, 30-Sep-2024 02:08:12 GMT; Max-Age=3600; path=/; domain=www.novado.de; secure; HttpOnly; SameSite=Lax,X-Magento-Vary=13f1cbbaed1bfd10c999e6da4663d586e710b7054d90219f4bd558bb09537bdd; expires=Mon, 30-Sep-2024 02:08:12 GMT; Max-Age=3600; path=/; secure; HttpOnly; SameSite=Lax |
link: |
</media/jk_bild_upload/02-b2c-hp/novado-check-icon.png>; rel=preload; as=image, </media/jk_bild_upload/02-b2c-hp/novado-check-icon.png>; rel=preload; as=image, </media/jk_bild_upload/02-b2c-hp/novado-check-icon.png>; rel=preload; as=image, </media/logo/websites/1/novado-b2c-logo-2023-header-3.png>; rel=preload; as=image, </media/logo/websites/1/novado-b2c-logo-2023-header-3.png>; rel=preload; as=image, </media/catalog/category/novado-startseite-oktoberfest-rabatt-desktop.jpg>; rel=preload; as=image, </media/catalog/category/Startseite_novado_1.jpg>; rel=preload; as=image, </media/catalog/category/startseite-banner-neuheiten-effect-strawberry-apricot-9mile-pornstar-martini-pink-rush-scavi-ray-moscato-frizzante-desktop.jpg>; rel=preload; as=image, </media/catalog/category/startseite-banner-lillet-wild-berry-aperol-spritz-spar-paket-desktop.jpg>; rel=preload; as=image, </media/jk_bild_upload/02-b2c-hp/1_1Pakete_Banner_Website_1920x800_1.jpg>; rel=preload; as=image, </static/version1725373180/frontend/Wmdk/novado/de_DE/requirejs/require.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/requirejs-min-resolver.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/js/bundle/bundle0.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/js/bundle/bundle1.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/js/bundle/bundle10.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/js/bundle/bundle11.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/js/bundle/bundle12.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/js/bundle/bundle13.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/js/bundle/bundle14.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/js/bundle/bundle15.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/js/bundle/bundle16.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/js/bundle/bundle17.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/js/bundle/bundle18.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/js/bundle/bundle19.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/js/bundle/bundle2.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/js/bundle/bundle20.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/js/bundle/bundle21.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/js/bundle/bundle22.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/js/bundle/bundle23.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/js/bundle/bundle24.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/js/bundle/bundle3.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/js/bundle/bundle4.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/js/bundle/bundle5.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/js/bundle/bundle6.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/js/bundle/bundle7.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/js/bundle/bundle8.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/js/bundle/bundle9.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/mage/requirejs/static.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/mage/requirejs/mixins.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/requirejs-config.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/Dm_DefaultShipping/js/dmDefaultShipping.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/js/magezon/page_builder.min.js>; rel=preload; as=script, </static/version1725373180/frontend/Wmdk/novado/de_DE/Smile_ElasticsuiteTracker/js/tracking.min.js>; rel=preload; as=script, </static/version1725373180/_cache/merged/orig_9b3cb40ea7152018063077c7f0039f6b.min.css>; rel=preload; as=style, </static/version1725373180/frontend/Wmdk/novado/de_DE/css/styles-l.min.css>; rel=preload; as=style, </static/version1725373180/frontend/Wmdk/novado/de_DE/fonts/bahnschrift/BAHNSCHRIFT.woff>; rel=preload; as=font; crossorigin=anonymous, </static/version1725373180/frontend/Wmdk/novado/de_DE/Magezon_Core/webfonts/fa-brands-400.woff2>; rel=preload; as=font; crossorigin=anonymous, </static/version1725373180/frontend/Wmdk/novado/de_DE/icon-fonts/font/porto-icons.woff2>; rel=preload; as=font; crossorigin=anonymous |
pragma: |
no-cache |
cache-control: |
max-age=0, must-revalidate, no-cache, no-store, no-cache, private |
expires: |
Fri, 29 Sep 2023 22:56:06 GMT |
content-security-policy-report-only: |
font-src *.fontawesome.com https://fonts.bunny.net *.gstatic.com 'self' data: https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://www.sandbox.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.weltpixel.com *.google.com/ secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com https://www.magezon.com *.sooqr.com https://api.mapbox.com cdn.pay1.de x.klarnacdn.net *.cloudfront.net *.hsforms.net *.hsforms.com 'self' data: https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.gstatic.com *.facebook.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.google.com *.sooqr.com secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io *.hsforms.net *.hsforms.com *.gstatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://fonts.bunny.net *.sooqr.com d.ratepay.com d.payla.io dr.payla.io *.googleapis.com *.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io payments.amazon.de d.ratepay.com jsctool.com eu.playground.klarnaevt.com autocomplete2.postdirekt.de t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.facebook.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri https://www.paypalobjects.com 'self' 'unsafe-inline'; |
x-content-type-options: |
nosniff |
x-xss-protection: |
1; mode=block |
x-frame-options: |
SAMEORIGIN |
|