date: |
Tue, 01 Oct 2024 00:41:24 GMT |
content-type: |
text/html |
transfer-encoding: |
chunked |
connection: |
close |
content-security-policy: |
base-uri 'self'; default-src 'self' data: 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' 78651v.a.searchspring.io *.adsrvr.org *.aftership.com *.akamaihd.net *.bing.com *.boltdns.net *.brightcovecdn.com *.cf.brightcove.com *.creativecdn.com *.criteo.com *.criteo.net *.doubleclick.net *.espssl.com *.g.doubleclick.net *.google-analytics.com *.googletagmanager.com *.listrak.com *.listrakbi.com *.media.brightcove.com *.myunidays.com *.playground.klarna.com *.playground.klarnaevt.com *.playground.klarnaservices.com *.prod.boltdns.net *.quantserve.com *.returnscenter.com *.snapchat.com *.sync.ad.cpe.dotomi.com *.taboola.com *.twitter.com *.typekit.net *.yotpo.com ajax.googleapis.com arttrk.com blob: cdn-widgetsrepository.yotpo.com ct.pinterest.com d3cgm8py10hi0z.cloudfront.net evt-eu.klarnaservices.com filesystem hls.ak.o.brightcove.com http://localhost http://localhost:3000 http://localhost:3100 https://api.keen.io https://assets.rise-ai.com https://beacon.searchspring.io https://builder.io https://cdn.builder.io https://cdn.builder.io https://cdn.jsdelivr.net https://cdn.shopify.com https://contact.gorgias.help https://data.debugbear.com/ https://fonts.gstatic.com https://maps.googleapis.com https://maps.gstatic.com https://metrics.brightcove.com https://players.brightcove.net https://storemapper-herokuapp-com.global.ssl.fastly.net https://storemapper.co https://str.rise-ai.com https://toms.returns.international https://unpkg.com https://www.google.com https://www.storemapper.co js.klarna.com na.klarnaevt.com osm.klarnaservices.com sc-static.net t.co tagmanager.google.com tags.creativecdn.com vjs.zencdn.net www.youtube.com x.klarnacdn.net cdn.cookielaw.org *.onetrust.com www.google.com *.securedvisit.com track.sv.rkdms.com agkn.com safevisit.online s3.amazonaws.com *.gorgias.chat *.gorgias.io *.gorgias.work https://storage.googleapis.com *.id.me *.metrics.convertexperiments.com logs.convertexperiments.com *.convertexperiments.com 'self' 'nonce-5414eb8a1308fa0ede88644e5d80c715' https://cdn.shopify.com https://shopify.com; frame-ancestors 'self' http://localhost http://localhost:3000 http://localhost:3100 https://cdn.shopify.com https://cdn.builder.io https://builder.io https://www.youtube.com *.listrakbi.com *.listrak.com *.yotpo.com *.securedvisit.com track.sv.rkdms.com agkn.com safevisit.online *.gorgias.chat *.gorgias.io *.gorgias.work https://storage.googleapis.com *.id.me *.metrics.convertexperiments.com logs.convertexperiments.com *.convertexperiments.com; style-src 'self' data: 'unsafe-inline' *.listrakbi.com *.typekit.net *.yotpo.com http://localhost http://localhost:3000 http://localhost:3100 https://builder.io https://cdn.builder.io https://cdn.jsdelivr.net https://cdn.shopify.com https://fonts.googleapis.com https://fonts.gstatic.com https://maps.gstatic.com players.brightcove.net ws://localhost:8002 x.klarnacdn.net cdn.cookielaw.org www.googletagmanager.com *.securedvisit.com track.sv.rkdms.com agkn.com safevisit.online s3.amazonaws.com *.gorgias.chat *.gorgias.io *.gorgias.work https://storage.googleapis.com *.id.me *.metrics.convertexperiments.com logs.convertexperiments.com *.convertexperiments.com 'self' 'unsafe-inline' https://cdn.shopify.com; connect-src 'self' *.akamaihd.net *.amplitude.com *.billypx.com *.bing.com *.boltdns.net *.cookielaw.org *.creativecdn.com *.criteo.com *.g.doubleclick.net *.google-analytics.com *.google.com *.googlesyndication.com *.gorgias.chat *.intentiq.com *.listrak.com *.listrakbi.com *.onetrust.com *.playground.klarna.com *.playground.klarnaevt.com *.playground.klarnaservices.com *.snapchat.com *.taboola.com *.tiktok.com *.toms.com *.yotpo.com *.myunidays.com *.prod.unidays.io *.safevisit.online ct.pinterest.com edge.api.brightcove.com evt-eu.klarnaservices.com hits.getelevar.com http://localhost http://localhost:3000 http://localhost:3100 https://api.keen.io https://application.rise-ai.com https://beacon.searchspring.io https://builder.io https://cdn.builder.io https://data.debugbear.com https://manifest.prod.boltdns.net https://maps.googleapis.com https://storemapper-herokuapp-com.global.ssl.fastly.net https://storemapper.co https://unpkg.com https://www.storemapper.co js.klarna.com na.klarnaevt.com osm.klarnaservices.com placehold.co players.brightcove.net staticw2.yotpo.com ws://localhost:8002 wss://*.gorgias.chat wss://perfect-alive-akita.ngrok-free.app www.youtube.com www.google.com x.klarnacdn.net 78651v.a.searchspring.io *.securedvisit.com track.sv.rkdms.com agkn.com safevisit.online *.liadm.com *.amazon-adsystem.com *.paa-reporting-advertising.amazon *.yottaa.net *.gorgias.chat *.gorgias.io *.gorgias.work https://storage.googleapis.com *.id.me *.metrics.convertexperiments.com logs.convertexperiments.com *.convertexperiments.com 'self' https://monorail-edge.shopifysvc.com; font-src 'self' data: *.typekit.net *.unidays.world *.yotpo.com cdn.shopify.com fonts.googleapis.com fonts.gstatic.com mediacdn.espssl.com x.klarnacdn.net *.securedvisit.com track.sv.rkdms.com agkn.com safevisit.online *.gorgias.chat *.gorgias.io *.gorgias.work https://storage.googleapis.com *.id.me *.metrics.convertexperiments.com logs.convertexperiments.com *.convertexperiments.com; img-src 'self' data: *; media-src blob: *.akamaihd.net manifest.prod.boltdns.net *.securedvisit.com track.sv.rkdms.com agkn.com safevisit.online *.gorgias.chat *.gorgias.io *.gorgias.work https://storage.googleapis.com *.id.me *.metrics.convertexperiments.com logs.convertexperiments.com *.convertexperiments.com; frame-src *.adsrvr.org *.aftership.com *.bing.com *.creativecdn.com *.criteo.com *.doubleclick.net *.g.doubleclick.net *.gorgias.chat *.gorgias.help *.klarnaservices.com *.listrak.com *.quantserve.com *.rise-ai.com *.snapchat.com *.sync.ad.cpe.dotomi.com *.taboola.com *.twitter.com arttrk.com ct.pinterest.com *.returnscenter.com t.co www.myunidays.com *.toms.com toms.returns.international s3.amazonaws.com hosted-pages.id.me *.securedvisit.com track.sv.rkdms.com agkn.com safevisit.online *.amazon-adsystem.com *.gorgias.chat *.gorgias.io *.gorgias.work https://storage.googleapis.com *.id.me *.metrics.convertexperiments.com logs.convertexperiments.com *.convertexperiments.com |
oxygen-full-page-cache: |
uncacheable |
powered-by: |
Shopify, Oxygen, Hydrogen |
x-request-id: |
o2-741d5a12-a302-4c2a-8bde-603c6f21afc5.8cb868270df2b778 |
x-shopid: |
74105291043 |
set-cookie: |
__cf_bm=17cOSaHyIllHUlArQ1HuoIEK3yNHq9F.eo2vQnC69lU-1727743284-1.0.1.1-mhTnBbdQlmyYmtuzrDYuwe1t4VY0QQJTYMA6VaDsAhzJklh0yZl.JjXApwGaH37d_iajl8t.zPJh3HicYcoSqA; path=/; expires=Tue, 01-Oct-24 01:11:24 GMT; domain=.www.toms.com; HttpOnly; Secure; SameSite=None |
report-to: |
{"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=P0bYwDh9Btqo5fyPTHRwhdCjRdNZpEVrny7J85gmWzYTon83Zmdc4D%2BZz0IDKfUcNpVtYDu1rI5vXvt%2BjoZO5sx%2F%2BUURUtmLJRpsVRamGgrvUPMOt6MV8spJxbISvg%3D%3D"}],"group":"cf-nel","max_age":604800} |
nel: |
{"success_fraction":0.01,"report_to":"cf-nel","max_age":604800} |
server: |
cloudflare |
cf-ray: |
8cb868270df2b778-AMS |