date: |
Tue, 01 Oct 2024 07:24:34 GMT |
content-type: |
text/html; charset=UTF-8 |
transfer-encoding: |
chunked |
connection: |
close |
accept-ch: |
Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA |
critical-ch: |
Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA |
cross-origin-embedder-policy: |
require-corp |
cross-origin-opener-policy: |
same-origin |
cross-origin-resource-policy: |
same-origin |
origin-agent-cluster: |
?1 |
permissions-policy: |
accelerometer=(),autoplay=(),browsing-topics=(),camera=(),clipboard-read=(),clipboard-write=(),geolocation=(),gyroscope=(),hid=(),interest-cohort=(),magnetometer=(),microphone=(),payment=(),publickey-credentials-get=(),screen-wake-lock=(),serial=(),sync-xhr=(),usb=() |
referrer-policy: |
same-origin |
x-content-options: |
nosniff |
x-frame-options: |
SAMEORIGIN |
cf-mitigated: |
challenge |
cf-chl-out: |
PQx+/M8V5VkL6MdWGp3BKw36Q/qTpxkhOjIUo9hGKBKDP47N061zs5fG5Ix/csZh0wEyUMoJtrVKao/UhWMPlbmktIOn68S1MHEw4QsZbp0pucB1ETKr9Y9h6WVSru6GIiRFh6IlF2f8VOyhxamruA==$Vu00NML3WFUjYgEG/vZRBA== |
cache-control: |
private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0 |
expires: |
Thu, 01 Jan 1970 00:00:01 GMT |
set-cookie: |
__cf_bm=._sVm4ixAW..turZq.mZiobRmntePRxMtMCqdKhPRNw-1727767474-1.0.1.1-9llP7B91hzhDcZGof8TF2y8uI3v.sRA.XxsFPmGQqiWOLRb7W0NCztSfr4omZrfFZHKePIGBSAyZJhhO8mZx9w; path=/; expires=Tue, 01-Oct-24 07:54:34 GMT; domain=.drybar.com; HttpOnly; Secure; SameSite=None |
content-security-policy: |
base-uri 'self' 'unsafe-inline'; child-src 'self' http: https: blob: 'unsafe-inline'; connect-src 'self' *.rapidspike.com www.cloudflare.com commerce.adobedtm.com commerce.adobedc.net *.snplow.net dpm.demdex.net api.magento.com commerce.adobe.io performance.typekit.net commerce.adobe.net amcglobal.sc.omtrdc.net www.googletagmanager.com www.googleadservices.com www.google-analytics.com analytics.google.com google.com *.analytics.google.com stats.g.doubleclick.net us-central1-adaptive-growth.cloudfunctions.net app-measurement.com doubleclickbygoogle.com doubleclick.com doubleclick.net googleadservices.com googlesyndication-cn.com googlesyndication.com googletagservices.com *.google.co.uk *.google.fr *.google.de *.google.es *.google.it *.google.nl *.google.be *.google.pl *.google.se *.google.ie *.google.dk *.google.pt *.google.gr *.google.fi *.google.cz *.google.hu *.google.at *.google.ro *.google.sk *.google.si *.google.bg *.google.hr *.google.lt *.google.lv *.google.ee *.google.mt *.google.cy *.google.lu *.google.us *.google.com.au *.google.ca *.google.com.pr *.google.com.mx *.google.co.cr *.google.com https://www.google.com/recaptcha/ *.recaptcha.net vimeo.com *.googlesyndication.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.stripe.network brilliantcollector.com *.brilliantcollector.com *.newrelic.com *.nr-data.net *.algolia.net *.algolia.com *.algolianet.com kustomerapp.com *.kustomerapp.com api.addressy.com ekr.zdassets.com parcellab.com *.parcellab.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com *.kaltura.com rapid-cdn.yottaa.com *.yottaa.net 'unsafe-inline' *.drybar.com *.listrakbi.com *.trustarc.com s.amazon-adsystem.com ara.paa-reporting-advertising.amazon *.algolia.io googletagmanager.com *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net www.facebook.com analytics.tiktok.com; font-src 'self' fonts.gstatic.com use.typekit.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.trustarc.com kustomerapp.com *.kustomerapp.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'unsafe-inline'; form-action 'self' yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'unsafe-inline' www.facebook.com; frame-ancestors 'self' www.gstatic.com stripe.com *.stripe.com; manifest-src 'self' 'unsafe-inline'; media-src 'self' *.adobe.com 'unsafe-inline' *.vimeo.com download-video.akamaized.net blob: data:; object-src 'self' 'unsafe-inline'; style-src 'self' *.adobe.com fonts.googleapis.com parcellab.com *.parcellab.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com *.googleapis.com 'unsafe-inline' cdn.listrakbi.com googletagmanager.com *.googletagmanager.com tagmanager.google.com; worker-src 'unsafe-eval' 'unsafe-inline' 'self' drybar.com/p/1/2; upgrade-insecure-requests; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=fRWBTB95eN8ZwzfprJk2ZORkHV2KYj4Xl4sD8eJwV6k-1727767474-1.0.1.1-N1gYmaUZq3D8dmTvw2PWSt2PVtfSbeLM.HvoLTSbk5z23MHFCuUr0W83Cg5MTFVYkr6vOYZy5awxAMWbj4xd.nhkcWCNzSB0bWi_aoKq3.uXbkfA7opBdiWn9VQhjcD_MJHy6RSdWqR0Cp__3tKUyPFyCidgIPqbO7nlGTiNo9I.b4Ow17Tsq1PksYvO8VrW5rwhonCHc0Nzv.3ksD2rjw; report-to cf-cegcwdcifetwfkve, frame-src 'self' fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net player.vimeo.com vimeo.com https://www.google.com/recaptcha/ *.recaptcha.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.stripe.network consent-pref.trustarc.com helenoftroy.demdex.net *.kustomer.support *.kustomer.help www.xtento.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'unsafe-inline' www.facebook.com *.googletagmanager.com td.doubleclick.net *.fls.doubleclick.net helpcenter.drybar.com services.listrak.com; img-src 'self' cdnjs.cloudflare.com widgets.magentocommerce.com assets.adobedtm.com dpm.demdex.net cm.everesttech.net *.adobe.com p.typekit.net amcglobal.sc.omtrdc.net www.googletagmanager.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com *.google.co.uk *.google.fr *.google.de *.google.es *.google.it *.google.nl *.google.be *.google.pl *.google.se *.google.ie *.google.dk *.google.pt *.google.gr *.google.fi *.google.cz *.google.hu *.google.at *.google.ro *.google.sk *.google.si *.google.bg *.google.hr *.google.lt *.google.lv *.google.ee *.google.mt *.google.cy *.google.lu *.google.us *.google.com.au *.google.ca *.google.com.pr *.google.com.mx *.google.co.cr *.vimeocdn.com validator.swagger.io *.trustarc.com *.112.2o7.net kustomerapp.com *.kustomerapp.com *.kustomerhostedcontent.com parcellab.com *.parcellab.com www.xtento.com cdn.xtento.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com yotpo-editor-production.s3.amazonaws.com *.kaltura.com data: 'unsafe-inline' www.facebook.com *.listrakbi.com google.com *.google.com www.gstatic.com ssl.gstatic.com googletagmanager.com *.googletagmanager.com fonts.googleapis.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net *.fls.doubleclick.net ad.doubleclick.net ade.googlesyndication.com; script-src 'self' *.rapidspike.com static.cloudflareinsights.com unpkg.com commerce.adobedtm.com assets.adobedtm.com *.adobe.com use.typekit.net commerce.adobe.net amcglobal.sc.omtrdc.net www.googletagmanager.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com magento-recs-sdk.adobe.net vimeo.com www.vimeo.com *.vimeocdn.com player.vimeo.com https://www.google.com/recaptcha/ *.recaptcha.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.stripe.network *.newrelic.com *.nr-data.net *.trustarc.com adobedtm.com *.algolia.net kustomerapp.com *.kustomerapp.com s7.addthis.com parcellab.com *.parcellab.com www.xtento.com cdn.xtento.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com *.kaltura.com rapid-cdn.yottaa.com 'unsafe-inline' 'unsafe-eval' cdn.jsdelivr.net connect.facebook.net analytics.tiktok.com *.analytics.tiktok.com c.amazon-adsystem.com *.listrakbi.com *.listrak.com ajax.googleapis.com *.ajax.googleapis.com googletagmanager.com *.googletagmanager.com tagmanager.google.com www.google.com https://www.gstatic.com/recaptcha/ *.cloudflare.com; worker-src 'unsafe-eval' 'unsafe-inline' 'self' drybar.com/p/2/2; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=GS8Dty789FI0QLPah3s56kjPVw0BzKnhR1.fReRUpl4-1727767474-1.0.1.1-ewbMnKWucOgWgFfRWdkbgFtcz2bErgxcNH_x9RafC7m.JEqxHJcHFmQd8wqbAO.wa9ZOVJuM_wUjyHuvwamJ9T684.Jx.SAI49MV_.W952cOsnplyRKqYejfNDIvJKmYJ4s6kCjicTzTg7p0KGZl_om7iVYd6QaG62dXpLafBMpO166v1VRlP28N0_vbW67JDO.Zr3C0SKDjOFk0wu4CNg; report-to cf-rwgjzcrmvthenzpu |
report-to: |
{"endpoints":[{"url":"https:\/\/csp-reporting.cloudflare.com\/cdn-cgi\/script_monitor\/report?m=fRWBTB95eN8ZwzfprJk2ZORkHV2KYj4Xl4sD8eJwV6k-1727767474-1.0.1.1-N1gYmaUZq3D8dmTvw2PWSt2PVtfSbeLM.HvoLTSbk5z23MHFCuUr0W83Cg5MTFVYkr6vOYZy5awxAMWbj4xd.nhkcWCNzSB0bWi_aoKq3.uXbkfA7opBdiWn9VQhjcD_MJHy6RSdWqR0Cp__3tKUyPFyCidgIPqbO7nlGTiNo9I.b4Ow17Tsq1PksYvO8VrW5rwhonCHc0Nzv.3ksD2rjw"}],"group":"cf-cegcwdcifetwfkve","max_age":86400}, {"endpoints":[{"url":"https:\/\/csp-reporting.cloudflare.com\/cdn-cgi\/script_monitor\/report?m=GS8Dty789FI0QLPah3s56kjPVw0BzKnhR1.fReRUpl4-1727767474-1.0.1.1-ewbMnKWucOgWgFfRWdkbgFtcz2bErgxcNH_x9RafC7m.JEqxHJcHFmQd8wqbAO.wa9ZOVJuM_wUjyHuvwamJ9T684.Jx.SAI49MV_.W952cOsnplyRKqYejfNDIvJKmYJ4s6kCjicTzTg7p0KGZl_om7iVYd6QaG62dXpLafBMpO166v1VRlP28N0_vbW67JDO.Zr3C0SKDjOFk0wu4CNg"}],"group":"cf-rwgjzcrmvthenzpu","max_age":86400} |
server: |
cloudflare |
cf-ray: |
8cbab6ba6e3566b6-AMS |
|