content-type: |
text/html; charset=utf-8 |
x-powered-by: |
Express |
x-xss-protection: |
1; mode=block |
content-security-policy: |
default-src * blob:; script-src data: 'self' 'unsafe-inline' 'unsafe-eval' *.nr-data.net *.newrelic.com *.hongkongdisneyland.com *.go.com *.wdpromedia.com *.content.disney.io *.disneyinternational.com *.wdprapps.disney.com connect.facebook.net *.scorecardresearch.com *.dilcdn.com *.wdpro.wdig.com *.tt.omtrdc.net dpm.demdex.net assets.adobedtm.com tags.bkrtx.com d1ivexoxmp59q7.cloudfront.net disneyparks.sp1.convertro.com stags.bluekai.com tags.bluekai.com bat.bing.com *.doubleclick.net *.clicktale.net s.yimg.com/wi/ytc.js *.ads-twitter.com *.twitter.com *.facebook.com *.lpsnmedia.net *.liveperson.net *.googleadservices.com *.yahoo.com tag.mtrcs.samba.tv *.proofhq.com *.googletagmanager.com *.google-analytics.com static.tacdn.com *.resonate.com *.reson8.com *.sojern.com *.appdynamics.com *.eum-appdynamics.com *.go-mpulse.net *.akstat.io *.gam-apigw.wdprapps.disney.com *.disney.com www.googletagmanager.com tagmanager.google.com *.demdex.net *.contentsquare.com *.cookielaw.org *.onetrust.com *.apptentive.com *.bluekai.com *.branch.io app.link www.googleadservices.com www.google.com snap.licdn.com cdn.resonate.com sc-static.net *.snapchat.com analytics.tiktok.com js.adsrvr.org; img-src * data: *.lpsnmedia.net *.akstat.io *.clicktale.net *.contentsquare.net *.google-analytics.com *.googletagmanager.com *.cookielaw.org www.google.com px.ads.linkedin.com; style-src 'self' 'unsafe-inline' *.lpsnmedia.net *.go.com *.wdpromedia.com *.wdprapps.disney.com *.liveperson.net *.gam-apigw.wdprapps.disney.com *.twdc.com tagmanager.google.com fonts.googleapis.com *.apptentive.com; frame-src 'self' *.go.com *.fls.doubleclick.net stags.bluekai.com tags.bluekai.com assets.adobedtm.com *.lpsnmedia.net *.liveperson.net *.facebook.com *.tamgrt.com *.flashtalking.com *.clicktale.net disney.idmelabs.com disney.id.me *.demdex.net cdn1.parksmedia.wdprapps.disney.com cdn2.parksmedia.wdprapps.disney.com *.go-mpulse.net *.akstat.io *.gam-apigw.wdprapps.disney.com s.amazon-adsystem.com *.bluekai.com *.doubleclick.net *.snapchat.com *.adsrvr.org *.disney.com *.wdpromedia.com 'unsafe-eval' 'unsafe-inline' www.googletagmanager.com tagmanager.google.com *.tt.omtrdc.net blob:; connect-src wss://*.liveperson.net *.liveperson.net *.lpsnmedia.net 'self' *.disney.com *.go.com *.demdex.net adobedc.demdex.net edge.adobedc.net *.tt.omtrdc.net *.akstat.io *.go-mpulse.net *.clicktale.net *.contentsquare.net r.disneystore.com r.disney.com r.disney.go.com r.starwars.com r.disneyjunior.com r.babble.com r.disneybaby.com *.google-analytics.com *.analytics.google.com analytics.google.com *.googletagmanager.com *.cookielaw.org *.onetrust.com *.apptentive.com bat.bing.com *.branch.io *.doubleclick.net cdn.linkedin.oribi.io *.reson8.com *.snapchat.com analytics.tiktok.com s.yimg.com; media-src blob: *.lpsnmedia.net *.wdprapps.disney.com; font-src * data: fonts.gstatic.com; child-src data: 'self' 'unsafe-inline' 'unsafe-eval' *.nr-data.net *.newrelic.com *.hongkongdisneyland.com *.go.com *.wdpromedia.com *.content.disney.io *.disneyinternational.com *.wdprapps.disney.com connect.facebook.net *.scorecardresearch.com *.dilcdn.com *.wdpro.wdig.com *.tt.omtrdc.net dpm.demdex.net assets.adobedtm.com tags.bkrtx.com d1ivexoxmp59q7.cloudfront.net disneyparks.sp1.convertro.com stags.bluekai.com tags.bluekai.com bat.bing.com *.doubleclick.net *.clicktale.net s.yimg.com/wi/ytc.js *.ads-twitter.com *.twitter.com *.facebook.com *.lpsnmedia.net *.liveperson.net *.googleadservices.com *.yahoo.com tag.mtrcs.samba.tv *.proofhq.com *.googletagmanager.com *.google-analytics.com static.tacdn.com *.resonate.com *.reson8.com *.sojern.com *.appdynamics.com *.eum-appdynamics.com *.go-mpulse.net *.akstat.io *.gam-apigw.wdprapps.disney.com *.disney.com www.googletagmanager.com tagmanager.google.com *.demdex.net *.contentsquare.com *.cookielaw.org *.onetrust.com *.apptentive.com *.bluekai.com *.branch.io app.link www.googleadservices.com www.google.com snap.licdn.com cdn.resonate.com sc-static.net *.snapchat.com analytics.tiktok.com js.adsrvr.org blob:; worker-src data: 'self' 'unsafe-inline' 'unsafe-eval' *.nr-data.net *.newrelic.com *.hongkongdisneyland.com *.go.com *.wdpromedia.com *.content.disney.io *.disneyinternational.com *.wdprapps.disney.com connect.facebook.net *.scorecardresearch.com *.dilcdn.com *.wdpro.wdig.com *.tt.omtrdc.net dpm.demdex.net assets.adobedtm.com tags.bkrtx.com d1ivexoxmp59q7.cloudfront.net disneyparks.sp1.convertro.com stags.bluekai.com tags.bluekai.com bat.bing.com *.doubleclick.net *.clicktale.net s.yimg.com/wi/ytc.js *.ads-twitter.com *.twitter.com *.facebook.com *.lpsnmedia.net *.liveperson.net *.googleadservices.com *.yahoo.com tag.mtrcs.samba.tv *.proofhq.com *.googletagmanager.com *.google-analytics.com static.tacdn.com *.resonate.com *.reson8.com *.sojern.com *.appdynamics.com *.eum-appdynamics.com *.go-mpulse.net *.akstat.io *.gam-apigw.wdprapps.disney.com *.disney.com www.googletagmanager.com tagmanager.google.com *.demdex.net *.contentsquare.com *.cookielaw.org *.onetrust.com *.apptentive.com *.bluekai.com *.branch.io app.link www.googleadservices.com www.google.com snap.licdn.com cdn.resonate.com sc-static.net *.snapchat.com analytics.tiktok.com js.adsrvr.org blob: |
x-disney-internal-spa-host: |
ip-10-26-18-187.ec2.internal |
etag: |
W/"XWOOLjgdRG7glPELquffJQ==" |
x-akamai-transformed: |
9 177766 0 pmb=mTOE,1 |
cache-control: |
no-cache, no-store, must-revalidate, post-check=0, pre-check=0 |
expires: |
Tue, 01 Oct 2024 20:29:39 GMT |
date: |
Tue, 01 Oct 2024 20:29:39 GMT |
transfer-encoding: |
chunked |
connection: |
close, Transfer-Encoding |
set-cookie: |
geolocation_aka_hkdl_jar=%7B%22zipCode%22%3A%22%22%2C%22region%22%3A%22%22%2C%22country%22%3A%22NL%22%2C%22metro%22%3A%22AMSTERDAM%22%2C%22metroCode%22%3A%22%22%7D; path=/; secure,languageSelection_jar_aka=%7B%22preferredLanguage%22%3A%22en_US%22%2C%22version%22%3A%221%22%2C%22precedence%22%3A0%2C%22language%22%3A%22en_US%22%2C%22akamai%22%3A%22true%22%7D; expires=Wed, 02-Oct-2024 20:29:39 GMT; path=/; secure,localeCookie_jar_aka=%7B%22contentLocale%22%3A%22en_US%22%2C%22version%22%3A%223%22%2C%22precedence%22%3A0%2C%22akamai%22%3A%22true%22%7D; expires=Wed, 02-Oct-2024 20:29:39 GMT; path=/; secure,_abck=C212472BDDB56FE0970DC0D4BF5647FD~-1~YAAQjkd7XMH2NDOSAQAAHzXGSQw2JulRG9x4q4/6rIL1L0+M6RGfjY0HXskjnIazu3H2x6pENMjeqLjMcMfolrPVGjHimfZLCVeXS6nlLD4TWq+T8U6a15LqTVPamSH+VxkJwUUWJTGBh9CaDcs6tYxl5rAyYQkXLrx/BQYvyQGJpXZPivTX0+uSO6CijAz2sCyaBxo7jTpVXfK2Qvr0FRJlxjFg0n0LYahmQpQeRQtbNZx9zkB3DMBrdpAHHwNmO60Xh3mE/VfafGh44NCSzkndLlQKcc/eXgtOZZB3FtPPlVGVDR9bfu+MJgSnOjLRLl1N6iQVLBrLxiaOgHhBGz/mWHLdSmKk+JUz+gQ4cbVfM3i0e1mgSsZ3GCRBj6hWF3jZ0Y/3Q2xdXJG3vK5pvnSdzBdsLQD0mSKDlXr06abfylj4HUehgnU=~-1~-1~-1; Domain=.hongkongdisneyland.com; Path=/; Expires=Wed, 01 Oct 2025 20:29:39 GMT; Max-Age=31536000; Secure,bm_sz=EDBB44755A37E6CA439A7BBAB6623108~YAAQjkd7XML2NDOSAQAAHzXGSRkCGrKt5PEW+gk2I//kkbDQVEiSa/UaOoWEHy50dQAnjxEnfvUoOTzgPVTGvZWLUiULz2BMRUfwkqjdautAElykSIzAYJTTw5RAVwRTAv8RiCiIWH75oydmwkLtCumvh9ZbKqTQvj9a2VqDQjA5gByjCtQnCeNvJIYu6AIG/3auQPzd+DDMjvt3EpFgiW/zxkvQo/yMzg5rjlaqMoAMZjzohuzdgW9ibOgJsQNLovFfjcFr/2NVfDeoz77y4L9jJztpeZANWXz+ljyTBETymLw2aFqGhvGVTt/PSCm1KthIVF+3OJaI52BglERe4jwgBTs0Vqg3qTAwIcnQjiDlOUAzW5dy5t0R+XhQgnfzfGB+y4mzXuB2YI0+8Q==~4277828~4405573; Domain=.hongkongdisneyland.com; Path=/; Expires=Wed, 02 Oct 2024 00:29:39 GMT; Max-Age=14400 |
strict-transport-security: |
max-age= 31536000; includeSubDomains |
x-disney-akamai-rule: |
FRONT-END-HTTPS, homepage spa-cache, HKDL homepage-spa Multiregion, CORS, US Locale Cookie, US Language Cookie, en language headers, Set geolocation_aka_hkdl_jar, Default Geolocation_aka_hkdl_jar |
access-control-max-age: |
86400 |
access-control-allow-credentials: |
false |
access-control-allow-headers: |
Content-Type, x-set-cart |
access-control-allow-methods: |
GET,POST,OPTIONS |
access-control-allow-origin: |
https://prodc.www.hongkongdisneyland.com |
x-disney-internal-site: |
hkdl |
x-frame-options: |
SAMEORIGIN |