content-security-policy-report-only: |
default-src 'self' https://media.nedigital.sg;script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://public-api.thor.zopsmart.com https://*.omni.fairprice.com.sg https://maps.googleapis.com https://*.doubleclick.net https://www.googleadservices.com https://*.google-analytics.com https://*.google.com https://www.facebook.com https://connect.facebook.net https://*.omguk.com https://*.googlesyndication.com https://*.fairprice.com.sg https://cdemux.appspot.com https://staticcdn.enzymic.co https://storage.googleapis.com https://110006471.collect.igodigital.com/collect.js https://fairprice.api.sociaplus.com/custom/fairprice https://s.yimg.com https://sp.analytics.yahoo.com/ https://t.contentsquare.net https://app.contentsquare.com https://*.bazaarvoice.com http://display.ugc.bazaarvoice.com/ http://stg.api.bazaarvoice.com/ http://api.bazaarvoice.com/ https://mpsnare.iesnare.com https://js.adsrvr.org/ https://analytics.tiktok.com/ https://snap.licdn.com/ https://px.ads.linkedin.com/ https://cdn.sprig.com/ https://cdn-assets-prod.s3.amazonaws.com https://*.abtasty.com https://*.googleapis.com https://*.salefinder.com.au https://*.nedigital.sg https://cdn.segment.com https://api.segment.io https://cdn.moengage.com https://app-cdn.moengage.com https://tags.creativecdn.com;connect-src 'self' https://cdn.linkedin.oribi.io/ https://analytics.google.com/ https://*.thor.zopsmart.com https://*.omni.fairprice.com.sg http://endpoint-publisher-service https://*.cybersource.com http://go-platform-website https://tagmanager.google.com https://*.doubleclick.net https://www.google-analytics.com https://connect.facebook.net https://www.facebook.com https://*.omguk.com https://*.fairprice.com.sg https://cdemux.appspot.com https://adservice.google.com https://static.enzymic.co https://fairprice.api.sociaplus.com/custom/fairprice https://*.plus.com.sg https://*.link.sg https://*.nedigital.sg https://s.yimg.com https://*.contentsquare.net *.plus.com.sg *.link.sg wss://api.preprod.link.sg wss://api.link.sg https://*.split.io https://stg.api.bazaarvoice.com/ http://api.bazaarvoice.com/ https://api.amplitude.com https://js.adsrvr.org/ https://analytics.tiktok.com/ https://snap.licdn.com/ https://px.ads.linkedin.com/ https://*.abtasty.com/ https://cdn.sprig.com/ https://api.sprig.com/ https://api.userleap.com/ https://api2.abtasty.com/ https://rum.browser-intake-datadoghq.com https://segment.com https://in.ap1.segmentapis.com https://api.segment.com https://track.segment.com https://api.segment.io https://sdk-01.moengage.com https://cdn.segment.com https://browser-intake-datadoghq.com https://asia.creativecdn.com https://www.google.com/pay https://pay.google.com/* https://checkoutshopper.adyen.com/checkoutshopper/v2/analytics/id https://checkoutshopper.adyen.com/checkoutshopper/v2/analytics/log https://www.google.com/ccm/collect https://google.com/pay https://pay.google.com/gp/p/payment_method_manifest.json https://pay.google.com/gp/p/web_manifest.json;img-src 'self' data: https://*.doubleclick.net https://*.salefinder.com.au https://*.cloudfront.net *;style-src 'self' 'unsafe-inline' https://tagmanager.google.com https://*.gstatic.com https://*.googleapis.com https://*.bazaarvoice.com/ http://display.ugc.bazaarvoice.com/ https://*.abtasty.com https://*.salefinder.com.au https://*.nedigital.sg https://app-cdn.moengage.com/ https://fonts.bunny.net/;frame-src 'self' https://preprod-auth.ntuclink.com.sg/ https://preprod-auth.ntuclink.com.sg/ https://auth.ntuclink.com.sg/ https://auth.fairprice.com.sg/ https://secureacceptance.cybersource.com/ http://www.surveygizmo.com/ https://*.fls.doubleclick.net https://www.googletagmanager.com https://www.facebook.com http://*.fls.doubleclick.net https://display.ugc.bazaarvoice.com https://stg.api.bazaarvoice.com http://api.bazaarvoice.com/ https://insight.adsrvr.org/ https://match.adsrvr.org/ https://*.abtasty.com/ https://www.pay.nedigital.sg/ https://pay.google.com/ https://cdn.moengage.com/ https://asia.creativecdn.com https://td.doubleclick.net/ https://www.google.com/pay https://pay.google.com/* https://checkoutshopper.adyen.com/checkoutshopper/v2/analytics https://checkoutshopper.adyen.com;font-src 'self' data: blob: https://*.gstatic.com https://*.googleapis.com https://*.abtasty.com https://*.nedigital.sg;child-src 'self' blob:;worker-src 'self' blob:;media-src 'self' https://s3-us-west-2.amazonaws.com/int-foodlab.storage/public/recipes/videos/ https://www.innit.com/public/recipes/videos/;frame-ancestors 'self' https://*.salefinder.com.au https://*.fairprice.com.sg;form-action 'self' https://www.pay.nedigital.sg/api/emv/authentications https://secureacceptance.cybersource.com/silent/embedded/pay https://secureacceptance.cybersource.com/silent/pay;base-uri 'self';object-src 'none';script-src-attr 'none';upgrade-insecure-requests |
cross-origin-opener-policy: |
same-origin |
cross-origin-resource-policy: |
same-origin |
origin-agent-cluster: |
?1 |
referrer-policy: |
strict-origin-when-cross-origin |
strict-transport-security: |
max-age=15768000; includeSubDomains; preload |
x-content-type-options: |
nosniff |
x-dns-prefetch-control: |
on |
x-download-options: |
noopen |
x-frame-options: |
SAMEORIGIN |
x-permitted-cross-domain-policies: |
none |
x-xss-protection: |
0 |
access-control-allow-origin: |
* |
etag: |
"bc566a8jzsmt0j" |
content-type: |
text/html; charset=utf-8 |
server-timing: |
init; dur=13.164268999999999; desc="Init time", total; dur=233.47248199999999; desc="Total Response Time" |
expires: |
Tue, 01 Oct 2024 08:54:40 GMT |
cache-control: |
max-age=0, no-cache, no-store |
pragma: |
no-cache |
date: |
Tue, 01 Oct 2024 08:54:40 GMT |
transfer-encoding: |
chunked |
connection: |
close, Transfer-Encoding |
set-cookie: |
splitSessionKey=629244_GUEST; Max-Age=31536; Path=/; Expires=Tue, 01 Oct 2024 17:40:16 GMT; HttpOnly; Secure; SameSite=Strict,connect.sid=s%3AeXcnbzRYgiraTc1WAoR_3-1iYkYqxnyB.wjZ%2FkNM6ys47lGFh9jWQv7glafgpyJav%2F%2F9fl4pq8Kc; Domain=.fairprice.com.sg; Path=/; Expires=Wed, 02 Oct 2024 08:54:40 GMT; HttpOnly; Secure; SameSite=Lax |