date: |
Wed, 02 Oct 2024 09:46:10 GMT |
content-type: |
text/html; charset=utf-8 |
transfer-encoding: |
chunked |
connection: |
close |
cache-control: |
no-cache,no-store |
pragma: |
no-cache |
expires: |
-1 |
vary: |
Accept-Encoding |
set-cookie: |
CurrentContact=71bafa55-26c7-4e21-8a40-0bd3b87dc42b; expires=Thu, 20 Sep 2074 09:46:10 GMT; path=/; secure; samesite=lax,CurrentContactID=1444059; expires=Thu, 20 Sep 2074 09:46:10 GMT; path=/; secure; samesite=lax,CurrentContactID=1444059; expires=Thu, 20 Sep 2074 09:46:10 GMT; path=/; secure; samesite=lax,identity.authentication=; expires=Thu, 01 Jan 1970 00:00:00 GMT; path=/; secure; samesite=none; httponly,Identity.External=; expires=Thu, 01 Jan 1970 00:00:00 GMT; path=/; secure; samesite=lax; httponly,Identity.TwoFactorUserId=; expires=Thu, 01 Jan 1970 00:00:00 GMT; path=/; secure; samesite=lax; httponly,.AspNetCore.Cookies=; expires=Thu, 01 Jan 1970 00:00:00 GMT; path=/; secure; samesite=lax; httponly,.AspNetCore.Session=CfDJ8KdU2Jg5bBpIuP1xXJScPcDegUPy4aoHX%2B36r7L8MX%2FEV31LlusQaau6%2Fi8NQTR%2BYMt991ZP1Xcu6nrfdV9nuHvlrBZOhf9mVZWg76%2BAfIvLpqsQCZaz8xolnVLw4lKvwvDzSv8%2Fibq%2BzWNwQg98VtwOuK8vtCZQszouE%2B1%2F6ZT3; path=/; secure; samesite=lax; httponly,__cflb=0H28vyjMCVzuRpyBfsfq6FC7kWMMcKoP58f8eNTUxoe; SameSite=Lax; path=/; expires=Thu, 03-Oct-24 08:46:10 GMT; HttpOnly |
content-security-policy-report-only: |
worker-src blob: *.osano.com; font-src 'self' data: *.gstatic.com; style-src 'self' data: fonts.googleapis.com *.leadoo.com 'unsafe-inline' *.osano.com; default-src 'self' 'unsafe-eval' data: media.hoddereducation.com; frame-src passport.hoddereducation.co.uk *.trustpayments.com *.securetrading.net *.secure.checkout.visa.com secure.checkout.visa.com *.cardinalcommerce.com pay.google.com thm.visa.com *.datadoghq-browser-agent.com *.browser-intake-datadoghq.eu *.trustpilot.com *.youtube.com *.vimeo.com *.osano.com td.doubleclick.net verify.monzo.com; connect-src *.algolia.net *.algolianet.com 'self' *.algolia.io *.sentry.io *.browser-intake-datadoghq.eu *.sentry.io google.com/pay *.cardinalcommerce.com *.fontawesome.com vimeo.com *.osano.com *.ads.linkedin.com analytics.tiktok.com *.analytics.google.com *.google-analytics.com *.googlesyndication.com *.hotjar.io www.google.com googleads.g.doubleclick.net ws.hotjar.com adservice.google.com analytics.google.com stats.g.doubleclick.net; frame-ancestors admin.hoddereducation.com 'self'; script-src cdn.eu.trustpayments.com 'self' *.securetrading.net *.secure.checkout.visa.com secure.checkout.visa.com *.cardinalcommerce.com *.datadoghq-browser-agent.com *.browser-intake-datadoghq.eu pay.google.com *.fontawesome.com *.trustpilot.com *.youtube.com *.vimeo.com *.cloudflare.com *.osano.com www.googletagmanager.com 'unsafe-inline' snap.licdn.com static.hotjar.com connect.facebook.net static.ads-twitter.com analytics.tiktok.com *.analytics.google.com script.hotjar.com googleads.g.doubleclick.net; img-src secure.checkout.visa.com *.secure.checkout.visa.com *.vims.visa.com 'self' media.hoddereducation.com data: resourcehub-resource-api.hodder.education analytics.twitter.com *.ads.linkedin.com www.facebook.com/tr www.facebook.com www.googletagmanager.com www.google.com t.co www.google.co.uk googleads.g.doubleclick.net; form-action 'self' *.cardinalcommerce.com *.securetrading.net verify.monzo.com; base-uri 'self'; report-uri https://www.hoddereducation.com/csp-report |
cross-origin-embedder-policy: |
unsafe-none |
cross-origin-opener-policy: |
same-origin |
cross-origin-resource-policy: |
same-site |
permissions-policy: |
accelerometer=(), battery=(), bluetooth=(), camera=(), display-capture=(), document-domain=(), geolocation=(), gyroscope=(), idle-detection=(), microphone=(), storage-access=(), usb=(), window-management=() |
cf-cache-status: |
DYNAMIC |
strict-transport-security: |
max-age=31536000; includeSubDomains; preload |
x-content-type-options: |
nosniff |
server: |
cloudflare |
cf-ray: |
8cc3c3888ed26569-AMS |
|