content-type: |
text/html; charset=UTF-8 |
content-length: |
221527 |
connection: |
close |
server: |
nginx |
date: |
Tue, 01 Oct 2024 11:24:15 GMT |
cache-control: |
max-age=300 |
x-xss-protection: |
1; mode=block |
x-frame-options: |
SAMEORIGIN |
x-content-type-options: |
nosniff |
last-modified: |
Sat, 28 Sep 2024 00:01:11 GMT |
strict-transport-security: |
max-age=31536000; includeSubDomains; |
referrer-policy: |
strict-origin |
origin-trial: |
AgPr4RwMtCVzULfBBSDLfibdCWWkxomQDgWsovO6c40YHx724W6X35YsXRDRhkx+6EBq2PuTgYjyJ1j89UhAfwEAAABleyJvcmlnaW4iOiJodHRwczovL3d3dy5haXJuZXd6ZWFsYW5kLmNvbTo0NDMiLCJmZWF0dXJlIjoiRmVhdHVyZVBvbGljeVJlcG9ydGluZyIsImV4cGlyeSI6MTU2MTI2Nzg4Nn0= |
report-to: |
{"group":"default", "max_age": 86400, "endpoints": [{"url": "/csp-report"}],"include_subdomains":true} |
feature-policy-report-only: |
fullscreen 'none'; autoplay 'none'; geolocation 'none'; camera 'none'; picture-in-picture 'none'; microphone 'none'; gyroscope 'none'; magnetometer 'none'; sync-xhr 'none'; accelerometer 'none'; midi 'none'; usb 'none'; |
nel: |
{"report_to":"default","max_age":31536000,"include_subdomains":true} |
content-security-policy: |
block-all-mixed-content; default-src 'self'; base-uri 'self'; form-action 'self' flightbookings.airnewzealand.co.kr flightbookings.airnewzealand.kr flightbookings.airnewzealand.ca flightbookings.airnewzealand.cn flightbookings.airnewzealand.co.nz flightbookings.airnewzealand.co.uk flightbookings.airnewzealand.com.au flightbookings.airnewzealand.com.hk flightbookings.airnewzealand.com.sg flightbookings.airnewzealand.com.tw flightbookings.airnewzealand.com flightbookings.airnewzealand.de flightbookings.airnewzealand.eu flightbookings.airnewzealand.fr flightbookings.airnewzealand.hk flightbookings.airnewzealand.jp flightbookings.airnewzealand.pf flightbookings.airnewzealand.tw flightbookings.airnewzealand.com.cn flightbookings.grabaseat.co.nz flightbookings.airnewzealand.co.jp au-connect.authsignal.com auth.identity.airnewzealand.com auth.identity.qual.airnewzealand.com; script-src 'self' p-airnz.com 'unsafe-inline' 'unsafe-eval' *.googleapis.com *.gstatic.com *.google.com *.ggpht.com *.googleusercontent.com player.vimeo.com www.youtube.com s.ytimg.com s.wayin.com xd.wayin.com s.engagesciences.com display.engagesciences.com www.everestjs.net *.demdex.net www.google-analytics.com analytics.google.com tagmanager.google.com www.googletagmanager.com *.doubleclick.net www.googleadservices.com www.google.com cdn-assets-prod.s3.amazonaws.com *.optimizely.com optimizely-hrd.appspot.com optimizely.s3.amazonaws.com s.swiftypecdn.com upgrade.plusgrade.com md-scp.kampyle.com sbt-prod.kampyle.com nebula-cdn.kampyle.com udc-neb.kampyle.com analytics-fe.digital-cloud-syd1.medallia.com.au static.hotjar.com script.hotjar.com yourir.info t.a3cloud.net ib.adnxs.com https://widget.timatic.iata.org/scripts/iata-timatic-widget-live.js oc-cdn-public-oce.azureedge.net; style-src 'unsafe-inline' p-airnz.com fonts.googleapis.com tagmanager.google.com s.swiftypecdn.com upgrade-cdn-prd.plusgrade.com static.hotjar.com script.hotjar.com yourir.info 'self' oc-cdn-public-oce.azureedge.net; img-src https: data: static.hotjar.com script.hotjar.com; font-src p-airnz.com fonts.googleapis.com fonts.gstatic.com dhm5hy2vn8l0l.cloudfront.net script.hotjar.com 'self' data:; media-src 'self' p-airnz.com video.cdnvue.com; frame-src 'self' *.google.com auth.identity.airnewzealand.com identity.airnewzealand.com au-connect.authsignal.com nz.fltmaps.com player.youku.com v.qq.com player.vimeo.com www.youtube.com airnz.wufoo.com xd.wayin.com display.engagesciences.com www.everestjs.net pixel.everesttech.net *.demdex.net *.doubleclick.net www.googletagmanager.com *.cdn-pci.optimizely.com nebula-cdn.kampyle.com vars.hotjar.com sec.windcave.com uat.windcave.com forms.cd.airnewzealand.co.nz www.airnewzealand.co.nz/airpoints-account/payments/scripts/done.html www.airnewzealand.co.nz/payment/scripts/done.html oc-cdn-public-oce.azureedge.net blob: airnz-cargo.chooose.today airnz-corporate.chooose.today; connect-src 'self' api.airnz.io api.airnz.ai *.googleapis.com *.google.com *.gstatic.com auth.airnewzealand.co.nz auth.airnewzealand.com identity.airnewzealand.com *.demdex.net *.tt.omtrdc.net www.google-analytics.com region1.google-analytics.com region1.analytics.google.com analytics.google.com stats.g.doubleclick.net adservice.google.com *.optimizely.com s.swiftypecdn.com search-api.swiftype.com md-scp.kampyle.com sbt-prod.kampyle.com nebula-cdn.kampyle.com udc-neb.kampyle.com analytics-fe.digital-cloud-syd1.medallia.com.au https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com https://*.sentry.io yourir.info https://widget.timatic.iata.org/api/ sec.windcave.com uat.windcave.com unq0355446423e84eb397bc71189d78d-crm6.omnichannelengagementhub.com; object-src 'none'; frame-ancestors 'self'; report-uri /csp-report |
permissions-policy: |
geolocation=(self "https://p-airnz.com"), camera=(), fullscreen=(self "https://www.youtube.com"), accelerometer=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), screen-wake-lock=(), sync-xhr=(*), usb=(), web-share=(), clipboard-read=(), clipboard-write=() |
vary: |
Accept-Encoding |
x-cache: |
Miss from cloudfront |
via: |
1.1 19392de11dadb918bd6f24e199ea180e.cloudfront.net (CloudFront) |
x-amz-cf-pop: |
MUC50-P3 |
alt-svc: |
h3=":443"; ma=86400 |
x-amz-cf-id: |
eh6LGhI_k5_ZJDP9VR_Ho7EY7rjOvwwRBEOxwTyWMG-OLugvIM39Jg== |