date: |
Tue, 01 Oct 2024 18:30:30 GMT |
content-type: |
text/html; charset=UTF-8 |
transfer-encoding: |
chunked |
connection: |
close |
server: |
Apache |
cache-control: |
must-revalidate, no-cache, private, no-store |
x-drupal-dynamic-cache: |
MISS |
link: |
<https://bimbobakeriesusa.com/>; rel="canonical", <https://bimbobakeriesusa.com/>; rel="shortlink" |
x-ua-compatible: |
IE=edge |
content-language: |
en |
x-content-type-options: |
nosniff, nosniff |
x-frame-options: |
SAMEORIGIN |
expires: |
Sun, 19 Nov 1978 05:00:00 GMT |
x-generator: |
Drupal 9 (https://www.drupal.org) |
content-security-policy: |
default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.cloudflare.com *.consumercare.net *.crazyegg.com *.facebook.net *.force.com *.formstack.com *.jsdelivr.net *.mousestats.com *.myfonts.net *.pinimg.com *.salesforce.com *.salesforceliveagent.com assets.juicer.io bbusf.my.site.com cdn.cookielaw.org maps.googleapis.com sc-static.net unpkg.com www.google-analytics.com www.google.com www.googletagmanager.com www.gstatic.com; style-src 'self' 'unsafe-inline' *.bimbobakeriesusa.com *.bootstrapcdn.com *.cloudflare.com *.force.com *.formstack.com *.googleapis.com *.gstatic.com *.jsdelivr.net *.myfonts.net *.salesforce.com *.typography.com assets.juicer.io bbusf.my.site.com unpkg.com; img-src 'self' *.adnxs.com *.adsrvr.org *.bbulibrary.com *.bimbobakeriesusa.com *.cdninstagram.com *.cookielaw.org *.doubleclick.net *.facebook.com *.formstack.com *.google.be *.google.bf *.google.bs *.google.ca *.google.ch *.google.cl *.google.co.il *.google.co.in *.google.co.ma *.google.co.nz *.google.co.th *.google.co.uk *.google.co.ve *.google.co.za *.google.co.zm *.google.com.ar *.google.com.au *.google.com.bd *.google.com.br *.google.com.cy *.google.com.do *.google.com.eg *.google.com.jm *.google.com.mx *.google.com.my *.google.com.ng *.google.com.ph *.google.com.pk *.google.com.pr *.google.com.sg *.google.com.tr *.google.de *.google.dz *.google.es *.google.fr *.google.hr *.google.hu *.google.ie *.google.lt *.google.mk *.google.nl *.google.ro *.google.si *.google.tn *.google.tt *.googleapis.com *.googletagmanager.com *.gstatic.com *.juicer.io *.myfonts.net bbusf.my.site.com cscoreproweustor.blob.core.windows.net data: translate.google.com trkn.us www.google-analytics.com www.google.com; frame-src 'self' *.doubleclick.net *.facebook.com *.force.com *.googletagmanager.com *.salesforce.com *.salesforceliveagent.com bbusf.my.site.com www.google.com www.youtube.com; frame-ancestors 'self'; font-src 'self' *.alicdn.com *.cdnfonts.com *.forms *.myfonts.net *.simplycodes.com *.slant.co *.tql.com *.typekit.net *.zip.co assets.merci-app.com bbusf.my.site.comtack.com data: fonts.gstatic.com maxcdn.bootstrapcdn.com sc-static.net static.juicer.io; connect-src 'self' *.bootstrapcdn.com *.channelsight.com *.clean.gg *.cookielaw.org *.doubleclick.net *.facebook.com *.fonts.net *.force.com *.google-analytics.com *.google.be *.google.bf *.google.ca *.google.ch *.google.co.il *.google.co.ma *.google.co.nz *.google.co.ve *.google.co.zm *.google.com *.google.com.au *.google.com.bd *.google.com.cy *.google.com.eg *.google.com.pr *.google.com.sg *.google.dz *.google.fr *.google.hr *.google.hu *.google.ie *.google.lt *.google.mk *.google.ro *.google.si *.google.tn *.googleapis.com *.googletagmanager.com *.juicer.io *.onetrust.com *.pricespider.com *.salesforce.com *.salesforceliveagent.com *.unpkg.com bbusf.my.site.com cdnjs.cloudflare.com cloud.typography.com streaming.split.io; report-uri https://gbnareports.report-uri.com/r/t/csp/enforce; upgrade-insecure-requests, default-src 'self' 'self' data: 'self' blob: 'unsafe-inline' 'unsafe-eval' *; img-src 'self' blob: data: * |
x-drupal-cache: |
HIT |
strict-transport-security: |
max-age=15552000 |
x-xss-protection: |
1; mode=block |
x-content-security-policy: |
default-src 'self' 'self' data: 'self' blob: 'unsafe-inline' 'unsafe-eval' *; img-src 'self' blob: data: * |
pragma: |
no-cache |