date: |
Tue, 01 Oct 2024 02:00:32 GMT |
content-type: |
text/html; charset=UTF-8 |
transfer-encoding: |
chunked |
connection: |
close |
accept-ch: |
Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA |
critical-ch: |
Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA |
cross-origin-embedder-policy: |
require-corp |
cross-origin-opener-policy: |
same-origin |
cross-origin-resource-policy: |
same-origin |
origin-agent-cluster: |
?1 |
permissions-policy: |
accelerometer=(),autoplay=(),browsing-topics=(),camera=(),clipboard-read=(),clipboard-write=(),geolocation=(),gyroscope=(),hid=(),interest-cohort=(),magnetometer=(),microphone=(),payment=(),publickey-credentials-get=(),screen-wake-lock=(),serial=(),sync-xhr=(),usb=() |
referrer-policy: |
same-origin |
x-content-options: |
nosniff |
x-frame-options: |
SAMEORIGIN |
cf-mitigated: |
challenge |
cf-chl-out: |
2C/6MMtjZcuDAOF82ExdkQLPYhHY3MXTMyvNOrF65FlB1RUpj34VxOj5De2y1/MviTaKxOgM8kxaH34DVGxccKWXkTNqL3kLWwlzqzOSadxeozi4RxcnuyM5jEXzradiSuUjtH0q4jXdZAICE3bTNQ==$vsZXavulKDV4YJ4Ikp59VA== |
cache-control: |
private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0 |
expires: |
Thu, 01 Jan 1970 00:00:01 GMT |
set-cookie: |
__cf_bm=4uuaMMODys9gxdpNc0Qoh.O0X8.yPwV1hswhXkfYXxw-1727748032-1.0.1.1-It7POn.yd.a_wt3Cl2Ro072XbxKHfVBVAwdx2NZ_CG22DuvIlGIsKT04a0Mk.qQQNXQOTgmtJXLT54na_gY.pw; path=/; expires=Tue, 01-Oct-24 02:30:32 GMT; domain=.hydroflask.com; HttpOnly; Secure; SameSite=None |
content-security-policy: |
base-uri 'self' 'unsafe-inline' 'unsafe-eval'; child-src assets.braintreegateway.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; connect-src *.amazon-adsystem.com *.stripe.network www.recaptcha.net yotpo-media-temporary.s3.amazonaws.com evnt.byspotify.com *.tiktok.com *.teads.tv *.googlesyndication.com *.addressy.com *.klaviyo.com *.datadome.co insights.algolia.io *.locally.com *.yottaa.net hydro-flask.pxf.io adservice.google.com www.google.com google.com cdn.kustomerapp.com links.services.disqus.com analytics.google.com *.sdiapi.com dpm.demdex.net *.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com *.adobe.io performance.typekit.net commerce.adobedtm.com commerce.adobedc.net api.magento.com www.sandbox.paypal.com www.paypalobjects.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.algolia.net *.algolia.com *.algolianet.com *.yotpo.com ekr.zdassets.com/ *.iterable.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com gov-bam.nr-data.net bam.nr-data.net stats.g.doubleclick.net *.oxo.com helenoftroy.tt.omtrdc.net hydroflask-sandbox.api.kustomerapp.com oxo-sandbox.api.kustomerapp.com hydroflask.api.kustomerapp.com oxo.api.kustomerapp.com services.postcodeanywhere.co.uk *.parcellab.com *.rapidspike.com *.brilliantcollector.com cloud.vimeo.com vimeo.com *.clarity.ms bat.bing.com *.kaltura.com *.spectrumcustomizer.com *.acq.io ssl.geoplugin.net *.yimg.com *.pndsn.com m.addthis.com ct.pinterest.com pinterest.com ak.sail-horizon.com www.facebook.com public.fbot.me api.sail-personalize.com 'self' 'unsafe-inline' googletagmanager.com *.googletagmanager.com *.analytics.google.com *.g.doubleclick.net *.google.com www.googleadservices.com *.google-analytics.com *.trustarc.com cdn.jsdelivr.net services.sheerid.com mpsnare.iesnare.com; font-src *.sdiapi.com *.klaviyo.com *.gstatic.com use.typekit.net *.yotpo.com *.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.hydroflask.com *.oxo.com cdn.kustomerapp.com *.trustarc.com *.lightboxcdn.com *.spectrumcustomizer.com data: 'self' 'unsafe-inline' fonts.gstatic.com; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.sandbox.paypal.com *.yotpo.com *.iterable.com *.cardinalcommerce.com *.paypal.com *.oxo.com *.brilliantcollector.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; manifest-src 'self' 'unsafe-inline'; media-src download-video.akamaized.net *.kaltura.com cfvod.kaltura.com *.adobe.com *.oxo.com *.vimeocdn.com player.vimeo.com vod-progressive.akamaized.net blob: data: cdnapisec.kaltura.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; style-src *.adobe.com *.klaviyo.com *.yotpo.com *.googleapis.com mageside.com *.mageside.com *.oxo.com *.pcapredict.com services.postcodeanywhere.co.uk *.lightboxcdn.com *.parcellab.com disqus.com c.disquscdn.com disquscdn.com z.moatads.com moatads.com addthisedge.com v1.addthisedge.com m.addthis.com v1.addthis.com addthis.com loggly.com logs-01.loggly.com ct.pinterest.com pinterest.com s.pinimg.com pinimg.com 'self' 'unsafe-inline' googletagmanager.com *.googletagmanager.com tagmanager.google.com fonts.googleapis.com cdn.jsdelivr.net; worker-src 'self' 'unsafe-inline' 'unsafe-eval' hydroflask.com/p/1/2 blob:; upgrade-insecure-requests; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=pvFuQqpT5yTvi7KZA37gbnRHwTAinMWPqODsUNEpPIU-1727748032-1.0.1.1-tl5RVaxEtQRHcBscAaG98.Z7sz4C1.WjGCKNnJyilDvy6EEyYnfhojt3AkN5L2U3mG67J.DNJX47NJAaK6a3UMc3WGo726YkBkWTR5wfrVq42vkDwMJQ2jx8wxm6lg7ToN4KrHEWLicjOlrh3QYzrb.efRT084xnlS3pTEaZ5URPP46cYs_aNKzq8dSKrWO5sfnBcfCK2jmO5gui5X83EA; report-to cf-dxazdwkwosqsmxwk, frame-src *.stripe.network www.recaptcha.net *.trustarc.com *.criteo.com *.criteo.net *.kmail-lists.com *.shopstylecollective.com app.collectivevoiceqa.com app.collectivevoice.com collectivevoice.com shopstylecollective.com *.googlesyndication.com *.sdiapi.com fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.sandbox.paypal.com player.vimeo.com *.youtube.com *.yotpo.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com doubleclick.net *.doubleclick.net hydroflask.attn.tv *.oxo.com *.lightboxcdn.com *.hydroflask.com *.brilliantcollector.com *.demdex.net *.kustomer.support *.kustomer.help *.locally.com *.facebook.com *.fbot.me addthisedge.com s7.addthis.com addthis.com disqus.com ct.pinterest.com pinterest.com insight.adsrvr.org match.adsrvr.org helenoftroy.custhelp.com s.amazon-adsystem.com ak.sail-horizon.com helenoftroy.demdex.net promotions.spredfast.com 'self' 'unsafe-inline' *.googletagmanager.com bid.g.doubleclick.net td.doubleclick.net *.fls.doubleclick.net www.google.com/recaptcha/ services.sheerid.com; img-src www.ojrq.net *.tiktok.com *.teads.tv cdnjs.cloudflare.com *.criteo.com *.criteo.net *.klaviyo.com *.cloudfront.net track.securedvisit.com match.adsrvr.org tracking.avantlink.com *.bazaarvoice.com insight.adsrvr.org googleads.g.doubleclick.net *.google.co.in google.co.in ce.lijit.com links.services.disqus.com cdn.viglink.com analytics.google.com www.google.com *.baidu.com *.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com p.typekit.net www.paypalobjects.com *.ftcdn.net *.behance.net fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.yotpo.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com *.paypal.com mageside.com *.mageside.com *.hydroflask.com hydroflask.attn.tv *.oxo.com *.lightboxcdn.com na-stage.hele.digital *.parcellab.com *.trustarc.com cfvod.kaltura.com *.bing.com *.clarity.ms *.hele.digital via.placeholder.com *.locally.com *.spectrumcustomizer.com stospectstageglobal.blob.core.windows.net blob: cdn.kustomerapp.com *.acq.io *.yimg.com loggly.com logs-01.loggly.com referrer.disqus.com c.disquscdn.com ct.pinterest.com pinterest.com sp.analytics.yahoo.com *.facebook.com scontent-iad3-2.cdninstagram.com stospectprodglobal.blob.core.windows.net 'self' 'unsafe-inline' google.com www.gstatic.com ssl.gstatic.com googletagmanager.com *.googletagmanager.com fonts.googleapis.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net *.fls.doubleclick.net ad.doubleclick.net ade.googlesyndication.com img.youtube.com *.google.com services.sheerid.com *.dl.dropboxusercontent.com *.dropbox.com; script-src cdnjs.cloudflare.com *.amazon-adsystem.com *.stripe.network www.recaptcha.net ajax.cloudflare.com static.cloudflareinsights.com pixel.byspotify.com *.teads.tv *.kervinteractive.com *.tiktok.com *.yottaa.net *.yottaa.com *.klaviyo.com safevisit.online *.criteo.com *.criteo.net *.impactcdn.com *.shopstylecollective.com app.collectivevoiceqa.com app.collectivevoice.com collectivevoice.com shopstylecollective.com *.rkdms.com lsdm.co track.securedvisit.com *.googlesyndication.com *.bazaarvoice.com ssl.avmws.com cdn.avmws.com analytics-static.ugc.bazaarvoice.com apps.bazaarvoice.com c.disquscdn.com cdn.kustomerapp.com unpkg.com *.sdiapi.com f.vimeocdn.com *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.google-analytics.com assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.paypalobjects.com js.braintreegateway.com commerce.adobedtm.com commerce.adobe.net www.sandbox.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.yotpo.com s7.addthis.com *.iterable.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com assets.braintreegateway.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com js-agent.newrelic.com bam.nr-data.net bam-cell.nr-data.net mageside.com *.mageside.com doubleclick.net *.hydroflask.com *.oxo.com *.pcapredict.com *.lightboxcdn.com *.locally.com lightboxapi.azurewebsites.net *.fbot.me services.postcodeanywhere.co.uk *.parcellab.com *.trustarc.com cdn-assets.rapidspike.com cdnapisec.kaltura.com *.brilliantcollector.com js.stripe.com connect.facebook.net bat.bing.com *.clarity.ms *.spectrumcustomizer.com js.acq.io ssl.geoplugin.net *.yimg.com ajax.googleapis.com cdn.pushplanet.com *.cloudfront.net moatads.com z.moatads.com addthisedge.com v1.addthisedge.com m.addthis.com v1.addthis.com addthis.com loggly.com logs-01.loggly.com hot.disqus.com hydroflask.disqus.com oxo.disqus.com stage-hydroflask.disqus.com stage-oxo.disqus.com preprod-hydroflask.disqus.com preprod-oxo.disqus.com prod-hydroflask.disqus.com prod-oxo.disqus.com ct.pinterest.com pinterest.com s.pinimg.com pinimg.com *.impactradius-event.com js.adsrvr.org insight.adsrvr.org ak.sail-horizon.com player.vimeo.com 'self' 'unsafe-inline' 'unsafe-eval' googletagmanager.com *.googletagmanager.com tagmanager.google.com www.gstatic.com/recaptcha/ www.google.com/recaptcha/ www.googleadservices.com www.google.com googleads.g.doubleclick.net cdn.jsdelivr.net mpsnare.iesnare.com; worker-src 'self' 'unsafe-inline' 'unsafe-eval' hydroflask.com/p/2/2 blob:; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=MJtftDwFbv6dIuMNwo_hKj3ARrkJnx5JOWLt8V50nhw-1727748032-1.0.1.1-wI6_zSFPgH66.GN246E6ljGX4HqZljTxlEe5uZQXQ2upk71YMjlk8zek9aqbKVItfLIS6KORY9l9NW7g.upedrx6unMKDHYRpysF_4UldH0wDVChP4OTX9Kocxe0ieQiXmS4L5E_W6rIOMCHdjlqgJgNX9CLfhmX.B9DOi_cJCfNkFgYtlAoat0s2.tRSDFSNJwl1oLAEXSXGPR_u6w6mg; report-to cf-aidhwlxnfbsrdrud |
report-to: |
{"endpoints":[{"url":"https:\/\/csp-reporting.cloudflare.com\/cdn-cgi\/script_monitor\/report?m=pvFuQqpT5yTvi7KZA37gbnRHwTAinMWPqODsUNEpPIU-1727748032-1.0.1.1-tl5RVaxEtQRHcBscAaG98.Z7sz4C1.WjGCKNnJyilDvy6EEyYnfhojt3AkN5L2U3mG67J.DNJX47NJAaK6a3UMc3WGo726YkBkWTR5wfrVq42vkDwMJQ2jx8wxm6lg7ToN4KrHEWLicjOlrh3QYzrb.efRT084xnlS3pTEaZ5URPP46cYs_aNKzq8dSKrWO5sfnBcfCK2jmO5gui5X83EA"}],"group":"cf-dxazdwkwosqsmxwk","max_age":86400}, {"endpoints":[{"url":"https:\/\/csp-reporting.cloudflare.com\/cdn-cgi\/script_monitor\/report?m=MJtftDwFbv6dIuMNwo_hKj3ARrkJnx5JOWLt8V50nhw-1727748032-1.0.1.1-wI6_zSFPgH66.GN246E6ljGX4HqZljTxlEe5uZQXQ2upk71YMjlk8zek9aqbKVItfLIS6KORY9l9NW7g.upedrx6unMKDHYRpysF_4UldH0wDVChP4OTX9Kocxe0ieQiXmS4L5E_W6rIOMCHdjlqgJgNX9CLfhmX.B9DOi_cJCfNkFgYtlAoat0s2.tRSDFSNJwl1oLAEXSXGPR_u6w6mg"}],"group":"cf-aidhwlxnfbsrdrud","max_age":86400} |
server: |
cloudflare |
cf-ray: |
8cb8dc129b9e7794-AMS |
|