date: |
Thu, 03 Oct 2024 06:25:55 GMT |
content-type: |
text/html; charset=utf-8 |
transfer-encoding: |
chunked |
connection: |
close |
set-cookie: |
ARRAffinity=90ead35c50fea541fad6ca622160a92f17519cccb8a005f2edea63e7a2472b8c;Path=/;HttpOnly;Secure;Domain=santaslapland.com,ARRAffinitySameSite=90ead35c50fea541fad6ca622160a92f17519cccb8a005f2edea63e7a2472b8c;Path=/;HttpOnly;SameSite=None;Secure;Domain=santaslapland.com |
strict-transport-security: |
max-age=31536000; includeSubDomains |
request-context: |
appId=cid-v1:a534a9d8-8257-43ce-bbba-3ef6f07526f5 |
permissions-policy: |
accelerometer=(), ambient-light-sensor=(), autoplay=(), camera=(), fullscreen=*, geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), speaker=(), sync-xhr=(), usb=(), vr=(), interest-cohort=() |
x-content-type-options: |
nosniff |
x-xss-protection: |
1; mode=block |
referrer-policy: |
strict-origin-when-cross-origin |
feature-policy: |
accelerometer 'none'; camera 'none'; geolocation 'none'; gyroscope 'none'; magnetometer 'none'; microphone 'none'; payment 'none'; usb 'none' |
x-permitted-cross-domain-policies: |
none |
x-frame-options: |
SAMEORIGIN |
expect-ct: |
max-age=0, report-uri=https://fiaf.report-uri.com/r/d/ct/reportOnly |
report-to: |
{"group":"wizard","max_age":10886400,"endpoints":[{"url":"https://crafted-umbraco.report-uri.com/a/d/g/wizard"}],"include_subdomains":true},{"group":"default","max_age":10886400,"endpoints":[{"url":"https://crafted-umbraco.report-uri.com/a/d/g"}],"include_subdomains":true} |
content-security-policy: |
default-src 'self'; script-src 'self' 'unsafe-eval' 'strict-dynamic' 'nonce-hcgIL8XY5SH9WCz/g7QjRDpa' *.cookielaw.org consentag.eu sahpsantaswebsiteliveuks.blob.core.windows.net *.googletagmanager.com cdn.ctnsnet.com *.google.com sdk.joinsherpa.io c0.adalyser.com *.yieldify.com connect.facebook.net www.dwin1.com ict.infinity-tracking.net cdn.livechatinc.com collector-8405.tvsquared.com d2oh4tlt9mrke9.cloudfront.net cdn.gbqofs.com ads.avocet.io bat.bing.com api.livechatinc.com ads.avct.cloud custom.yieldify.com cdnhpsantaswebsiteliveuks.azureedge.net *.google-analytics.com *.googleadservices.com *.googleoptimize.com *.abtasty.com *.yieldify.com 'unsafe-inline' blob: *.abtasty.com try.abtasty.com i.ctnsnet.com cdn.ctnsnet.com consentag.eu mcs.us1.twilio.com wss://tsock.us1.twilio.com api.talkdeskapp.com talkdeskchatsdk.talkdeskapp.com 'unsafe-inline' survey.survicate.com surveys-static.survicate.com; style-src 'self' *.typography.com data: 'unsafe-inline' *.craftedbeta.co.uk sahpsantaswebsiteliveuks.blob.core.windows.net cdnhpsantaswebsiteliveuks.azureedge.net *.googleapis.com try.abtasty.com *.abtasty.com 'unsafe-inline' surveys-static.survicate.com mcs.us1.twilio.com wss://tsock.us1.twilio.com api.talkdeskapp.com talkdeskchatsdk.talkdeskapp.com; img-src 'self' data: *.google.co.uk *.google.com *.google-analytics.com *.gstatic.com *.youtube.com *.umbraco.com *.vimeocdn.com res.cloudinary.com cdn.cookielaw.org secure.adnxs.com bat.bing.com collector-8405.tvsquared.com pixel.mediaiqdigital.com x.bidswitch.net jadserve.postrelease.com *.facebook.com *.doubleclick.net sync.go.sonobi.com us-u.openx.net simage2.pubmatic.com e1.emxdgt.com ce.lijit.com sync.teads.tv public-prod-dspcookiematching.dmxleo.com ads.betweendigital.com cpm.convergeselect.net usersync.gumgum.com eb2.3lift.com sync.search.spotxchange.com pixel.rubiconproject.com ad.360yield.com *.googletagmanager.com onetag-sys.com bh.contextweb.com contextual.media.net dsum.casalemedia.com partners.tremorhub.com s.pubmine.com match.sharethrough.com rtb-csync.smartadserver.com ads.avct.cloud dpm.demdex.net connect.facebook.net ws.sessioncam.com *.google.at c0.adalyser.com sofia.trustx.org sync.bfmio.com *.google.ca *.google.ch *.google.co.in *.google.co.th *.google.com.au *.google.com.mt *.google.com.ph *.google.com.pk *.google.com.tr *.google.com.ua *.google.de *.google.fi *.google.fr *.google.gr *.google.ie *.google.it *.google.kz *.google.se *.google.sk *.yieldify.com *.yieldify-production.com maps.googleapis.com *.engage.app *.eu-west-2.amazonaws.com editor-assets.abtasty.com *.abtasty.comi.ctnsnet.com cdn.ctnsnet.com consentag.eu mcs.us1.twilio.com wss://tsock.us1.twilio.com surveys-static.survicate.com assets.survicate.com img.survicate.com images.unsplash.com *.talkdeskdev.com *.talkdeskapp.com; frame-ancestors 'self'; connect-src 'self' *.googleapis.com *.google.com *.google.co.uk *.umbraco.com sahpsantaswebsiteliveuks.blob.core.windows.net *.cookielaw.org *.google-analytics.com geolocation.onetrust.com l.getsitecontrol.com ict.infinity-tracking.net ws.sessioncam.com cdnhpsantaswebsiteliveuks.azureedge.net *.g.doubleclick.net *.infinity-tracking.net *.facebook.com *.bing.com *.onetrust.com api.livechatinc.com *.googletagmanager.com *.yieldify.com *.applicationinsights.azure.com c2001.report.gbss.io *.abtasty.com *.yieldify.com *.yieldify-production.com *.infinity-tracking.com wss://stranger.yieldify-production.com *.engage.app i.ctnsnet.com cdn.ctnsnet.com consentag.eu mcs.us1.twilio.com wss://tsock.us1.twilio.com respondent.survicate.com *.talkdeskapp.eu; frame-src 'self' *.google.com *.youtube.com *.vimeo.com *.youtube-nocookie.com consentag.eu apps.joinsherpa.io *.fls.doubleclick.net td.yieldify.com *.facebook.com secure.livechatinc.com *.s3.amazonaws.com bid.g.doubleclick.net *.livechatinc.com mcs.us1.twilio.com wss://tsock.us1.twilio.com api.talkdeskapp.com talkdeskchatsdk.talkdeskapp.com; font-src 'self' data: sahpsantaswebsiteliveuks.blob.core.windows.net cdnhpsantaswebsiteliveuks.azureedge.net *.gstatic.com fonts.yieldify-production.com *.yieldify-production.com fonts.gstatic.com *.livechatinc.com *.abtasty.com mcs.us1.twilio.com wss://tsock.us1.twilio.com api.talkdeskapp.com talkdeskchatsdk.talkdeskapp.com surveys-static.survicate.com; object-src 'self'; media-src 'self' data: res.cloudinary.com; report-uri https://santaslaplnd.report-uri.com/r/d/csp/enforce; |
link: |
<https://res.cloudinary.com>; rel=preconnect, <https://cdnhpsantaswebsiteliveuks.azureedge.net>; rel=preconnect |