date: |
Fri, 04 Oct 2024 14:38:09 GMT |
content-type: |
text/html; charset=utf-8 |
transfer-encoding: |
chunked |
connection: |
close |
status: |
200 OK |
permissions-policy: |
microphone=(), camera=(), geolocation=(), fullscreen=(self), payment=(), screen-wake-lock=(), publickey-credentials-get=(), display-capture=(self) |
referrer-policy: |
strict-origin-when-cross-origin |
x-xss-protection: |
1; mode=block |
x-request-id: |
4b1631d6-7433-4588-b757-34e59037ce5b |
link: |
<https://d1y1ao4aj0rzc0.cloudfront.net/packs/css/application-d53836b9.chunk.css>; rel=preload; as=style; nopush,<https://d1y1ao4aj0rzc0.cloudfront.net/packs/js/runtime~application-bcc6e240ca2c6951c2f1.js>; rel=preload; as=script; nopush,<https://d1y1ao4aj0rzc0.cloudfront.net/packs/js/vendors~admin~admin-footer~admin-home~admin-menu~admin-sections~application~home~kiwisaver~menu~noti~63b6c05c-08c7553fa68a01646952.chunk.js>; rel=preload; as=script; nopush,<https://d1y1ao4aj0rzc0.cloudfront.net/packs/js/vendors~admin~application-cbc8a46ce9ac8a5e9522.chunk.js>; rel=preload; as=script; nopush,<https://d1y1ao4aj0rzc0.cloudfront.net/packs/js/application-2e77cea1530ca92330a1.chunk.js>; rel=preload; as=script; nopush,<https://d1y1ao4aj0rzc0.cloudfront.net/packs/js/runtime~menu-cb419f17092ee35a9fe4.js>; rel=preload; as=script; nopush,<https://d1y1ao4aj0rzc0.cloudfront.net/packs/js/vendors~admin-footer~admin-home~admin-menu~admin-sections~home~kiwisaver~menu~notifications~products~6b25e923-e112a05363acd9a8d6b5.chunk.js>; rel=preload; as=script; nopush,<https://d1y1ao4aj0rzc0.cloudfront.net/packs/js/menu-20fcd070dde4e073c5cf.chunk.js>; rel=preload; as=script; nopush,<https://d1y1ao4aj0rzc0.cloudfront.net/packs/js/runtime~notifications-0f3f25745591c4e839ae.js>; rel=preload; as=script; nopush,<https://d1y1ao4aj0rzc0.cloudfront.net/packs/js/notifications-fefdb0c2bb4cad009493.chunk.js>; rel=preload; as=script; nopush |
x-frame-options: |
SAMEORIGIN |
x-runtime: |
0.081268 |
x-content-type-options: |
nosniff |
content-security-policy: |
default-src 'self' *.consumer.org.nz; font-src *; img-src 'self' data: *; object-src 'none'; style-src 'self' 'unsafe-inline' *.consumer.org.nz *.marketo.com api.addressfinder.io *.googleapis.com consumer-nz-assets.s3.amazonaws.com uploads-cnz.s3-ap-southeast-2.amazonaws.com uploads-cnz.s3.ap-southeast-2.amazonaws.com optimize.google.com *.visualwebsiteoptimizer.com app.vwo.com embed.intentful.com d1y1ao4aj0rzc0.cloudfront.net; frame-src 'self' *.consumer.org.nz *.doubleclick.net *.marketo.com consumertest.shinyapps.io donorbox.org e.infogram.com *.spotify.com platform.twitter.com player.vimeo.com www.rnz.co.nz staticcdn.co.nz *.facebook.com www.googletagmanager.com www.iheart.com www.recaptcha.net www.youtube.com yabblezone.net survey.alchemer.com www.instagram.com optimize.google.com *.visualwebsiteoptimizer.com app.vwo.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.consumer.org.nz *.google-analytics.com munchkin.marketo.net *.marketo.com *.algolia.net *.algolianet.com api.addressfinder.io *.nr-data.net bat.bing.com bat.bing-int.com connect.facebook.net consumer-nz-assets.s3.amazonaws.com donorbox.org e.infogram.com platform.twitter.com player.vimeo.com staticcdn.co.nz uploads-cnz.s3-ap-southeast-2.amazonaws.com www.googletagmanager.com www.gstatic.com www.recaptcha.net www.youtube.com www.instagram.com *.googleapis.com translate.google.com cdnjs.cloudflare.com/ajax/libs/iframe-resizer/3.5.16/iframeResizer.min.js survey.alchemer.com www.surveygizmo.com www.googleoptimize.com optimize.google.com analytics.tiktok.com cdn.raygun.io www.googleadservices.com *.doubleclick.net ajax.cloudflare.com snap.licdn.com *.visualwebsiteoptimizer.com app.vwo.com widget.surveymonkey.com embed.intentful.com *.clarity.ms d1y1ao4aj0rzc0.cloudfront.net uploads-cnz.s3.amazonaws.com; connect-src 'self' *.consumer.org.nz *.marketo.net *.algolia.io *.algolia.net *.algolianet.com *.doubleclick.net *.google-analytics.com *.mktoresp.com *.mktoutil.com *.google.com api.addressfinder.io *.nr-data.net bat.bing.com bat.bing-int.com www.facebook.com www.instagram.com *.googleapis.com analytics.tiktok.com www.googletagmanager.com *.raygun.io cdn.linkedin.oribi.io px.ads.linkedin.com *.visualwebsiteoptimizer.com app.vwo.com api.intentful.com *.clarity.ms; worker-src 'self' blob:; report-uri https://report-to-api.raygun.com/reports-csp?apikey=0DrrEZ5IGC5CYxKjtrP5aA== |
fastly-hash: |
null-hash |
x-haunted-by: |
[email protected] |
strict-transport-security: |
max-age=31536000; includeSubDomains; preload |
age: |
391981 |
x-served-by: |
cache-ams21054-AMS |
x-cache: |
HIT |
x-cache-hits: |
0 |
x-timer: |
S1728052690.594165,VS0,VE1 |
vary: |
Fastly-Hash, Accept-Encoding |
cache-control: |
private, no-store |
cf-cache-status: |
DYNAMIC |
report-to: |
{"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=AyFRfmBKw1os%2FCpMqFzSGDVhKdQS1%2BJaZPlcAw3iPa6pIFY1vJKebEmIbf0Tt9d5sn9ArIt6n5a5Kb9QQQPt6RzDEi5gNqAcRjT5GvYqgaPkQUWOZ3pwWIQKmeI3uVENl55uaWM%3D"}],"group":"cf-nel","max_age":604800} |
nel: |
{"success_fraction":0,"report_to":"cf-nel","max_age":604800} |
server: |
cloudflare |
cf-ray: |
8cd5e9fdc9ab6564-AMS |