date: |
Thu, 03 Oct 2024 06:22:06 GMT |
content-type: |
text/html; charset=utf-8 |
transfer-encoding: |
chunked |
connection: |
close |
cache-control: |
no-cache, no-store, must-revalidate |
expires: |
-1 |
pragma: |
no-cache |
set-cookie: |
ASP.NET_SessionId=jgzwbxcrnf5bf1iib1zj5fjf; path=/; secure; HttpOnly; SameSite=Lax,ASP.NET_SessionId=jgzwbxcrnf5bf1iib1zj5fjf; path=/; secure; HttpOnly; SameSite=Lax,Cove.ExistingUser=True; expires=Sat, 03-Oct-2026 06:22:06 GMT; path=/; HttpOnly; SameSite=Lax,ASP.NET_SessionId=jgzwbxcrnf5bf1iib1zj5fjf; path=/; secure; HttpOnly; SameSite=Lax,Cove.ExistingUser=True; expires=Sat, 03-Oct-2026 06:22:06 GMT; path=/; HttpOnly; SameSite=Lax,__RequestVerificationToken=SJm3NSvLnT0ezcP-cUeUiKEKwrFSxl0erPvRLiJOmBWZxXg1Mu6ZAvoT5Fl_ACpgYpuHtCfBOHw0dPaXk5X7mDNB5gX7htpPPmzdohb68ac1; path=/; secure; HttpOnly,ARRAffinity=2407e7c87a2ddff4352517bc9d64689f745f15f2659d071f36699ed42f5340dc;Path=/;HttpOnly;Secure;Domain=www.sacoapartments.com,ARRAffinitySameSite=2407e7c87a2ddff4352517bc9d64689f745f15f2659d071f36699ed42f5340dc;Path=/;HttpOnly;SameSite=None;Secure;Domain=www.sacoapartments.com |
vary: |
Accept-Encoding,Accept-Encoding |
strict-transport-security: |
max-age=31536000; includeSubDomains |
content-security-policy-report-only: |
font-src fonts.gstatic.com *.typekit.net 'self' apps.mews.li *.mews.com data:; img-src *.googleapis.com *.lpsnmedia.net *.gstatic.com *.sacoapartments.com/en/join-cove 'self' *.mews.li *.mews.com *.bing.com *.duettoresearch.com *.onetrust.com cx.atdmt.com data: *.doubleclick.net *.googleusercontent.com *.quantserve.com *.lockeliving.com *.windows.net *.facebook.com *.google-analytics.com www.google.co.uk www.google.com www.googletagmanager.com www.gstatic.com www.google.ie *.googleapis.com *.ggpht.com; script-src maps.googleapis.com *.relay-t.io *.msecnd.net *.vo.msecnd.net *.liveperson.net *.lpsnmedia.net *.liveperson.net *.treasuredata.com https://cdn.jsdelivr.net/npm/flatpickr 'self' 'unsafe-eval' 'unsafe-inline' *.mews.li *.mews.com bat.bing.com capture.duettoresearch.com *.onetrust.com *.facebook.net *.doubleclick.net rules.quantcount.com secure.quantserve.com www.google-analytics.com www.google.com www.googleadservices.com www.googletagmanager.com www.gstatic.com fareharbor.com *.sacoapartments.com *.instagram.com *.msecnd.net; style-src *.googleapis.com cdn.jsdelivr.net/npm/flatpickr *.typekit.net 'self' 'unsafe-eval' 'unsafe-inline' *.lockeliving.com; connect-src *.triptease.io *.googlesyndication.com *.launchdarkly.com esp-eu.aptrinsic.com *.ingest.sentry.io *.newrelic.com *.googleapis.com *.liveperson.net google.com *.relay-t.io *.google.com *.onetrust.com 'self' *.mews.li *.mews.com bat.bing.com *.duettoresearch.com *.visualstudio.com *.doubleclick.net *.facebook.com *.google-analytics.com *.instagram.com; frame-src *.lpsnmedia.net *.Liveperson.net *.google.com *.doubleclick.net ms-appx-web://microsoft.microsoftedge *.facebook.com *.googletagmanager.com 'self' fareharbor.com gifer.com pay.datatrans.com *.onetrust.com *.instagram.com *.youtube.com *.clickdimensions.com *.lockeliving.com *.findingedyn.com; script-src-elem *.onetrust.com *.google.com *.msecnd.net web-sdk-eu.aptrinsic.com *.vo.msecnd.net *.liveperson.net p.relay-t.io cdn.jsdelivr.net/npm/flatpickr *.lpsnmedia.net *.gstatic.com 'self' 'unsafe-inline' *.mews.li *.mews.com *.bing.com *.duettoresearch.com *.facebook.net data: *.doubleclick.net *.googleapis.com *.lockeliving.com *.quantcount.com *.quantserve.com *.google-analytics.com *.googleadservices.com *.googletagmanager.com *.mews.li *.mews.com fareharbor.com *.datatrans.com *.instagram.com; default-src 'unsafe-eval' 'unsafe-inline' data: *.googleapis.com *.gstatic.com maps.googleapis.com www.google.com *.mews.li *.mews.com *.onetrust.com; media-src *.vimeo.com *.akamaized.net; script-src-attr 'unsafe-inline'; style-src-attr 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' *.typekit.net *.googleapis.com *.sacoapartments.com *.google.com web-sdk-eu.aptrinsic.com *.mews.com; child-src 'self' www.google.com blob:; manifest-src 'self'; report-uri https://sacoapartments.report-uri.com/r/d/csp/wizard |
link: |
<https://cdn-ukwest.onetrust.com/scripttemplates/otSDKStub.js>; rel=preload; as=script |
x-frame-options: |
SAMEORIGIN |
x-content-type-options: |
nosniff |
feature-policy: |
geolocation 'none'; |
permissions-policy: |
accelerometer=(), ambient-light-sensor=(), autoplay=(), camera=(), fullscreen=*, geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), speaker=(), sync-xhr=(), usb=(), vr=(), interest-cohort=() |
x-xss-protection: |
1; mode=block |
referrer-policy: |
no-referrer-when-downgrade |
x-permitted-cross-domain-policies: |
none |
cross-origin-opener-policy: |
same-origin; report-to='default' |
cross-origin-resource-policy-report-only: |
same-site; report-to='default' |
cross-origin-embedder-policy-report-only: |
require-corp; report-to='default' |
nel: |
{'report_to':'default','max_age':31536000,'include_subdomains':true} |
report-to: |
{'group':'default','max_age':31536000,'endpoints':[{'url':'https://sacoapartments.report-uri.com/a/d/g'}],'include_subdomains':true} |
cf-cache-status: |
DYNAMIC |
server: |
cloudflare |
cf-ray: |
8ccad5f62b820b5e-AMS |