content-type: |
text/html; charset=utf-8 |
cache-control: |
private, no-cache, no-store, max-age=0, must-revalidate |
content-security-policy: |
upgrade-insecure-requests;default-src 'nonce-bbab59e3209cf8d45e6425e4a312a4d2' 'self' 'nonce-595ebe3f58bdee08656fa6fd43b84ae4' 'unsafe-eval' 'unsafe-inline' *.bing.com *.bedbathandbeyond.com *.bedbathandbeyond.ca *.clarity.ms *.ostkcdn.com *.ostkcdn.com google.com *.google.com *.google.ca *.google-analytics.com *.google.co.uk *.googlesyndication.com *.googletagmanager.com *.newrelic.com *.nr-data.net bam.nr-data.net *.tiqcdn.com *.facebook.net *.facebook.com *.akamaihd.net *.doubleclick.net *.appboycdn.com *.braze.com *.creativecdn.com *.3gl.net cm.adform.net ih.adscale.de visitor.omnitagjs.com pixel.advertising.com ib.adnxs.com ice.360yield.com dsum-sec.casalemedia.com pixel.rubiconproject.com hbx.media.net cm.mgid.com onetag-sys.com us-u.openx.net sync.outbrain.com simage2.pubmatic.com bh.contextweb.com s.seedtag.com match.sharethrough.com s.ad.smaato.net us.ck-ie.com ce.lijit.com sync.taboola.com eb2.3lift.com s-cs.rmp.rakuten.com dot.wp.pl ad.yieldlab.net ads.yieldmo.com t.visx.net ssc-cms.33across.com pixel.s3xified.com inv-nets.admixer.net sync.connectad.io sync.e-planning.net csync.loopme.me adn.caprofitx.com sync.addlv.smt.docomo.ne.jp sync.1rx.io ssp-csync.smartadserver.com csync.smilewanted.com sync.teads.tv rt.udmserve.net sync.console.adtarget.com.tr visitor.omnitagjs.com rtb.gumgum.com dot.wp.pl cm-exchange.toast.com ad.as.amanad.adtdp.com sync.bidence.net cs.gssprt.jp sp.gmossp-sp.jp analytics.ad.daum.net s-cs.send.microad.jp mixer.mobon.net tg.socdm.com sync.ad-stir.com;connect-src 'self' *.overstock.com *.overstock.ca *.bedbathandbeyond.com *.bedbathandbeyond.ca *.bing.com *.clarity.ms *.ostkcdn.com *.ostkcdn.com google.com *.google.com *.google-analytics.com *.google.co.uk *.google.ca *.googletagmanager.com *.googlesyndication.com *.newrelic.com *.nr-data.net bam.nr-data.net *.tiqcdn.com *.tealiumiq.com *.facebook.net *.facebook.com *.akamaihd.net *.akstat.io *.doubleclick.net *.go-mpulse.net *.appboycdn.com *.creativecdn.com *.braze.com *.paypal.com *.3gl.net *.evergage.com cm.adform.net ih.adscale.de visitor.omnitagjs.com pixel.advertising.com ib.adnxs.com ice.360yield.com dsum-sec.casalemedia.com pixel.rubiconproject.com hbx.media.net cm.mgid.com onetag-sys.com us-u.openx.net sync.outbrain.com simage2.pubmatic.com bh.contextweb.com s.seedtag.com match.sharethrough.com s.ad.smaato.net us.ck-ie.com ce.lijit.com sync.taboola.com eb2.3lift.com s-cs.rmp.rakuten.com dot.wp.pl ad.yieldlab.net ads.yieldmo.com t.visx.net ssc-cms.33across.com pixel.s3xified.com inv-nets.admixer.net sync.connectad.io sync.e-planning.net csync.loopme.me adn.caprofitx.com sync.addlv.smt.docomo.ne.jp sync.1rx.io ssp-csync.smartadserver.com csync.smilewanted.com sync.teads.tv rt.udmserve.net sync.console.adtarget.com.tr visitor.omnitagjs.com rtb.gumgum.com dot.wp.pl cm-exchange.toast.com ad.as.amanad.adtdp.com sync.bidence.net cs.gssprt.jp sp.gmossp-sp.jp analytics.ad.daum.net s-cs.send.microad.jp mixer.mobon.net tg.socdm.com sync.ad-stir.com;img-src 'self' data: blob: *.ostkcdn.com *.overstock.com *.overstock.ca *.bedbathandbeyond.com *.bedbathandbeyond.ca *.bing.com *.clarity.ms *.cloudinary.com *.facebook.com ytimg.com *.ytimg.com *.google-analytics.com google.com *.google.com *.google.co.uk *.google.ca *.google.pl *.google.es *.google.com.ph *.google.com.pr *.google.co.ma *.google.co.in *.google.co.id *.google.am *.google.tt *.google.com.ng *.google.com.au *.google.it *.google.lv *.google.de *.google.lu *.google.nl *.google.com.br *.google.vg *.google.lk *.google.com.pk *.google.co.za *.google.ie *.google.rw *.google.com.eg *.google.com.vn *.gstatic.com *.google.com.hk *.google.com.et *.google.vg *.googlesyndication.com *.googletagmanager.com googleads.g.doubleclick.com *.akamaihd.net *.doubleclick.net appboy-images.com braze-images.com *.cdn.braze.eu *.appboycdn.com *.creativecdn.com *.braze.com *.paypal.com *.3gl.net cm.adform.net ih.adscale.de visitor.omnitagjs.com pixel.advertising.com ib.adnxs.com ice.360yield.com dsum-sec.casalemedia.com pixel.rubiconproject.com hbx.media.net cm.mgid.com 1ybaxwjk.micpn.com onetag-sys.com us-u.openx.net sync.outbrain.com simage2.pubmatic.com bh.contextweb.com s.seedtag.com match.sharethrough.com s.ad.smaato.net us.ck-ie.com ce.lijit.com sync.taboola.com eb2.3lift.com s-cs.rmp.rakuten.com dot.wp.pl ad.yieldlab.net ads.yieldmo.com t.visx.net ssc-cms.33across.com pixel.s3xified.com inv-nets.admixer.net sync.connectad.io sync.e-planning.net csync.loopme.me adn.caprofitx.com sync.addlv.smt.docomo.ne.jp sync.1rx.io ssp-csync.smartadserver.com csync.smilewanted.com sync.teads.tv rt.udmserve.net sync.console.adtarget.com.tr visitor.omnitagjs.com rtb.gumgum.com dot.wp.pl cm-exchange.toast.com ad.as.amanad.adtdp.com sync.bidence.net cs.gssprt.jp sp.gmossp-sp.jp analytics.ad.daum.net s-cs.send.microad.jp mixer.mobon.net tg.socdm.com sync.ad-stir.comscript-src-elem 'self' 'unsafe-inline' *.overstock.com *.overstock.ca *.bedbathandbeyond.com *.bedbathandbeyond.ca *.bing.com *.clarity.ms *.ostkcdn.com *.ostkcdn.com google.com *.google.com *.google-analytics.com *.google.co.uk *.googletagmanager.com *.googlesyndication.com *.googleadservices.com *.gstatic.com *.newrelic.com *.nr-data.net *.tiqcdn.com *.facebook.net *.facebook.com *.akamaihd.net *.doubleclick.net *.go-mpulse.net *.appboycdn.com *.creativecdn.com *.braze.com *.paypal.com *.3gl.net cm.adform.net ih.adscale.de visitor.omnitagjs.com pixel.advertising.com ib.adnxs.com ice.360yield.com dsum-sec.casalemedia.com pixel.rubiconproject.com hbx.media.net cm.mgid.com 1ybaxwjk.micpn.com onetag-sys.com us-u.openx.net sync.outbrain.com simage2.pubmatic.com bh.contextweb.com s.seedtag.com match.sharethrough.com s.ad.smaato.net us.ck-ie.com ce.lijit.com sync.taboola.com eb2.3lift.com s-cs.rmp.rakuten.com dot.wp.pl ad.yieldlab.net ads.yieldmo.com t.visx.net ssc-cms.33across.com pixel.s3xified.com inv-nets.admixer.net sync.connectad.io sync.e-planning.net csync.loopme.me adn.caprofitx.com sync.addlv.smt.docomo.ne.jp sync.1rx.io ssp-csync.smartadserver.com csync.smilewanted.com sync.teads.tv rt.udmserve.net sync.console.adtarget.com.tr visitor.omnitagjs.com rtb.gumgum.com dot.wp.pl cm-exchange.toast.com ad.as.amanad.adtdp.com sync.bidence.net cs.gssprt.jp sp.gmossp-sp.jp analytics.ad.daum.net s-cs.send.microad.jp mixer.mobon.net tg.socdm.com sync.ad-stir.com;script-src 'self' 'unsafe-inline' 'unsafe-eval' *.overstock.com *.overstock.ca *.bedbathandbeyond.com *.bedbathandbeyond.ca *.bing.com *.clarity.ms *.ostkcdn.com *.ostkcdn.com google.com *.google.com *.google-analytics.com *.google.co.uk *.gstatic.com *.googlesyndication.com *.googletagmanager.com *.googleadservices.com *.newrelic.com *.nr-data.net *.evgnet.com *.tiqcdn.com *.facebook.net *.facebook.com *.akamaihd.net *.doubleclick.net *.go-mpulse.net *.appboycdn.com *.creativecdn.com *.braze.com *.3gl.net cm.adform.net ih.adscale.de visitor.omnitagjs.com pixel.advertising.com ib.adnxs.com ice.360yield.com dsum-sec.casalemedia.com pixel.rubiconproject.com hbx.media.net cm.mgid.com 1ybaxwjk.micpn.com onetag-sys.com us-u.openx.net sync.outbrain.com simage2.pubmatic.com bh.contextweb.com s.seedtag.com match.sharethrough.com s.ad.smaato.net us.ck-ie.com ce.lijit.com sync.taboola.com eb2.3lift.com s-cs.rmp.rakuten.com dot.wp.pl ad.yieldlab.net ads.yieldmo.com t.visx.net ssc-cms.33across.com pixel.s3xified.com inv-nets.admixer.net sync.connectad.io sync.e-planning.net csync.loopme.me adn.caprofitx.com sync.addlv.smt.docomo.ne.jp sync.1rx.io ssp-csync.smartadserver.com csync.smilewanted.com sync.teads.tv rt.udmserve.net sync.console.adtarget.com.tr visitor.omnitagjs.com rtb.gumgum.com dot.wp.pl cm-exchange.toast.com ad.as.amanad.adtdp.com sync.bidence.net cs.gssprt.jp sp.gmossp-sp.jp analytics.ad.daum.net s-cs.send.microad.jp mixer.mobon.net tg.socdm.com sync.ad-stir.com;script-src-attr 'self' *.overstock.com *.overstock.ca 'unsafe-inline' *.bedbathandbeyond.com *.bedbathandbeyond.ca *.bing.com *.clarity.ms *.ostkcdn.com *.ostkcdn.com google.com *.google.com *.google-analytics.com *.google.co.uk *.googlesyndication.com *.googletagmanager.com *.newrelic.com *.nr-data.net *.tiqcdn.com *.facebook.net *.facebook.com *.akamaihd.net *.doubleclick.net *.appboycdn.com *.creativecdn.com *.3gl.net cm.adform.net ih.adscale.de visitor.omnitagjs.com pixel.advertising.com ib.adnxs.com ice.360yield.com dsum-sec.casalemedia.com pixel.rubiconproject.com hbx.media.net cm.mgid.com onetag-sys.com us-u.openx.net sync.outbrain.com simage2.pubmatic.com bh.contextweb.com s.seedtag.com match.sharethrough.com s.ad.smaato.net us.ck-ie.com ce.lijit.com sync.taboola.com eb2.3lift.com s-cs.rmp.rakuten.com dot.wp.pl ad.yieldlab.net ads.yieldmo.com t.visx.net ssc-cms.33across.com pixel.s3xified.com inv-nets.admixer.net sync.connectad.io sync.e-planning.net csync.loopme.me adn.caprofitx.com sync.addlv.smt.docomo.ne.jp sync.1rx.io ssp-csync.smartadserver.com csync.smilewanted.com sync.teads.tv rt.udmserve.net sync.console.adtarget.com.tr visitor.omnitagjs.com rtb.gumgum.com dot.wp.pl cm-exchange.toast.com ad.as.amanad.adtdp.com sync.bidence.net cs.gssprt.jp sp.gmossp-sp.jp analytics.ad.daum.net s-cs.send.microad.jp mixer.mobon.net tg.socdm.com sync.ad-stir.com;style-src 'self' 'unsafe-inline' *.overstock.com *.overstock.ca *.bedbathandbeyond.com *.bedbathandbeyond.ca *.bing.com *.clarity.ms *.doubleclick.net *.googlesyndication.com *.ostkcdn.com cm.adform.net ih.adscale.de visitor.omnitagjs.com pixel.advertising.com ib.adnxs.com ice.360yield.com dsum-sec.casalemedia.com pixel.rubiconproject.com hbx.media.net cm.mgid.com onetag-sys.com us-u.openx.net sync.outbrain.com simage2.pubmatic.com bh.contextweb.com s.seedtag.com match.sharethrough.com s.ad.smaato.net us.ck-ie.com ce.lijit.com sync.taboola.com eb2.3lift.com s-cs.rmp.rakuten.com dot.wp.pl ad.yieldlab.net ads.yieldmo.com t.visx.net ssc-cms.33across.com pixel.s3xified.com inv-nets.admixer.net sync.connectad.io sync.e-planning.net csync.loopme.me adn.caprofitx.com sync.addlv.smt.docomo.ne.jp sync.1rx.io ssp-csync.smartadserver.com csync.smilewanted.com sync.teads.tv rt.udmserve.net sync.console.adtarget.com.tr visitor.omnitagjs.com rtb.gumgum.com dot.wp.pl cm-exchange.toast.com ad.as.amanad.adtdp.com sync.bidence.net cs.gssprt.jp sp.gmossp-sp.jp analytics.ad.daum.net s-cs.send.microad.jp mixer.mobon.net tg.socdm.com sync.ad-stir.com;font-src 'self' *.overstock.com *.overstock.ca *.bedbathandbeyond.com *.bedbathandbeyond.ca *.gstatic.com *.3gl.net data:;object-src 'none';worker-src 'self' blob: blob *.overstock.com *.overstock.ca *.bedbathandbeyond.com *.bedbathandbeyond.ca *.ostkcdn.com;form-action 'self' *.overstock.com *.overstock.ca *.bedbathandbeyond.com *.bedbathandbeyond.ca *.facebook.com *.3gl.net; frame-src *.paypal.com *.bing.com *.clarity.ms *.facebook.com *.youtube.com google.com *.google.com *.googlesyndication.com *.googletagmanager.com *.overstock.com *.bedbathandbeyond.com *.creativecdn.com *.doubleclick.net *.3gl.net cm.adform.net ih.adscale.de visitor.omnitagjs.com pixel.advertising.com ib.adnxs.com ice.360yield.com dsum-sec.casalemedia.com pixel.rubiconproject.com hbx.media.net cm.mgid.com onetag-sys.com us-u.openx.net sync.outbrain.com simage2.pubmatic.com bh.contextweb.com s.seedtag.com match.sharethrough.com s.ad.smaato.net us.ck-ie.com ce.lijit.com sync.taboola.com eb2.3lift.com s-cs.rmp.rakuten.com dot.wp.pl ad.yieldlab.net ads.yieldmo.com t.visx.net ssc-cms.33across.com pixel.s3xified.com inv-nets.admixer.net sync.connectad.io sync.e-planning.net csync.loopme.me adn.caprofitx.com sync.addlv.smt.docomo.ne.jp sync.1rx.io ssp-csync.smartadserver.com csync.smilewanted.com sync.teads.tv rt.udmserve.net sync.console.adtarget.com.tr visitor.omnitagjs.com rtb.gumgum.com dot.wp.pl cm-exchange.toast.com ad.as.amanad.adtdp.com sync.bidence.net cs.gssprt.jp sp.gmossp-sp.jp analytics.ad.daum.net s-cs.send.microad.jp mixer.mobon.net tg.socdm.com sync.ad-stir.com; report-uri /api/report-content-security-policy-violation |
etag: |
W/"11jrgkc38bm977n" |
server: |
nginx/1.24.0 + Phusion Passenger(R) 6.0.19 |
status: |
200 OK |
x-powered-by: |
Phusion Passenger(R) 6.0.19 |
x-akamai-transformed: |
9 99751 0 pmb=mRUM,3 |
date: |
Tue, 01 Oct 2024 01:23:02 GMT |
transfer-encoding: |
chunked |
connection: |
close, Transfer-Encoding |
set-cookie: |
_csrf=th3go4xknY8-vDgIT3ikMTVy; Path=/; Secure; HttpOnly,CA_MICRO=1; expires=Sat, 05-Oct-2024 01:23:02 GMT; path=/; secure; SameSite=None,_abck=19A6AEE946DD81B5A433191B39163F3B~-1~YAAQn0d7XAcYhzGSAQAAw3KsRQwXIczCSzKi3GWWrx7ilCX2NakifmvmgplHqLieHpEJ4YwpyyCZpRMVr8yjmLBu/IHDCR85FoSWKyAhM242UoxznBxHN7LefYWbCtH6T4gxt88WdSAmERLoh9sJtFsrpmWj1cDwBXVPG4DpxA2ud1oDG5Q97M8Sry1i22u4/Bw4XrHSZouXPth5FFPCER4VxUcxRTxdrBcNb95wPRkrkNca6yaU/Xc3zWQLighdvLip3JIs0MMb5J+D3ZHWxzrYLHRvUNyH0F8FuTXEKonHlpqkhEycsFLTGRPkn1dwhlxg/vuHaA63c2mwTtkfZaVKyGYiKniVXkNPeLdURiQoQxP7FBBXKLRNZepACKKK+au3VRRZj6THuxa0xpfFpIpDT2GlZT2RaY6Z51myDn9LFMImogc=~-1~-1~-1; Domain=.bedbathandbeyond.ca; Path=/; Expires=Wed, 01 Oct 2025 01:23:02 GMT; Max-Age=31536000; Secure,bm_sz=5C8B7A627400073C2F32EABE03B691EE~YAAQn0d7XAgYhzGSAQAAw3KsRRmpu9tTCRLJYGPQvwK6zOhW+2kaRzveSKOWqGhXvYKqyB6iVLq6xaO7zxcpFewh+E99XVwCqV1q/N/l9pBzd8Excz7t4WIJ84BX6DPW75CElBA509GyAvZveZAtUTlyKRXnTFHzZFPOiF5wneZFSenqd/1Uaiz9k9B4HwMPLUh/BjAZMdFV54f+V4U6Wpo+mQaJSdiMz9x3Eea/xNKANCJxwdLmOEYp7urnI5yzmX09ngCdSkuQjmBoK0hpsJ7MBkSSlrjZ4RyYQIsRgNtbnwqlrhEwUTfqVTUKhdmVFqge2sTbiNQkjhWSf8YDsXrEl2NZVV+rZ8KORf56DCyI3YF59si6K7gBxnEXEx+Yrbre6yroWiQjJQ==~4539458~3290417; Domain=.bedbathandbeyond.ca; Path=/; Expires=Tue, 01 Oct 2024 05:23:02 GMT; Max-Age=14400 |
server-timing: |
cdn-cache; desc=MISS, edge; dur=111, origin; dur=230, ak_p; desc="1727745782071_1551583135_988708700_34013_10933_4_13_-";dur=1 |
x-ak-client-rtt: |
4 |
strict-transport-security: |
max-age=31536000 |
|