date: |
Mon, 30 Sep 2024 21:17:44 GMT |
content-type: |
text/html; charset=utf-8 |
transfer-encoding: |
chunked |
connection: |
close |
pragma: |
no-cache |
expires: |
Mon, 30 Sep 2024 19:04:17 GMT |
content-language: |
en-US |
xkey: |
ez-all l61 pl2 p1 p2 p61 c59 ct23 |
strict-transport-security: |
max-age=15768000; includeSubDomains; |
x-xss-protection: |
1; mode=block |
x-content-type-options: |
nosniff |
report-to: |
{'group':'default','max_age':3600,'endpoints':[{'url':'https://amnh.report-uri.com/a/t/g'}], {'group':'report-uri-amnh-csp-endpoint','max_age':3600,'endpoints':[{'https://amnh.report-uri.com/r/t/csp/enforce'}],'include_subdomains':true} |
nel: |
{'report_to':'default','max_age':3600,'include_subdomains':true} |
content-security-policy: |
default-src 'self' https://*.doubleclick.net https://stats.g.doubleclick.net; child-src blob: https://www.amnh.org; connect-src 'self' https://*.googlesyndication.com https://*.sentry.io https://analytics.tiktok.com https://*.abtasty.com https://region1.analytics.google.com https://analytics.google.com https://*.cloudflarestream.com https://*.doubleclick.net https://*.googleapis.com https://ask.hotjar.io https://*.hotjar.com https://*.videodelivery.net https://ad.doubleclick.net https://adservice.google.com https://apis.google.com https://cdn.syndication.twimg.com https://cdp.cloud.unity3d.com https://config.uca.cloud.unity3d.com https://edit.meridianapps.com https://googletagmanager.com https://media.amnh.org https://pixels.spotify.com https://region1.google-analytics.com https://starling.crowdriff.com https://stats.g.doubleclick.net https://surveystats.hotjar.io https://syndication.twitter.com https://tags.meridianapps.com https://translate.googleapis.com https://vc.hotjar.io https://www.facebook.com https://www.google-analytics.com https://www.google.al https://www.google.ca https://www.google.ch https://www.google.co.in https://www.google.co.tz https://www.google.co.uk https://www.google.com https://www.google.com.ar https://www.google.com.bd https://www.google.de https://www.google.es https://www.google.fr https://www.google.no https://www.google.ro wss://*.hotjar.com wss://tags.meridianapps.com wss://ws15.hotjar.com https://amnh.ungerboeck.com; font-src 'self' data: https://*.abtasty.com https://*.googleapis.com https://script.hotjar.com https://abs.twimg.com https://fonts.gstatic.com https://surveystats.hotjar.io https://ssl.p.jwpcdn.com https://use.typekit.net; form-action 'self' https://data.library.amnh.org https://digitallibrary.amnh.org https://export.highcharts.com https://www.googletagmanager.com https://libcat1.amnh.org https://platform.twitter.com https://syndication.twitter.com https://www.facebook.com; frame-ancestors 'self' https://*.google.com https://*.amnh.org https://amnh.org; frame-src 'self' https://*.abtasty.com https://*.cloudflarestream.com https://*.search.serialssolutions.com https://9432320.fls.doubleclick.net https://accounts.google.com https://amnh.uservoice.com https://bid.g.doubleclick.net https://block.opendns.com https://calendar.google.com https://consentag.eu https://d1eoo1tco6rr5e.cloudfront.net https://darwin.amnh.org https://docs.google.com https://embed.videodelivery.net https://giphy.com https://iframe.videodelivery.net https://*.adsrvr.org https://mead2019.sched.com https://m.facebook.com https://moodle.amnh.org https://osborn.amnh.org https://ourworldindata.org https://platform.twitter.com https://player.vimeo.com https://sketchfab.com https://syndication.twitter.com https://td.doubleclick.net https://tpc.googlesyndication.com https://useast-www.securly.com https://vars.hotjar.com https://videodelivery.net https://w.soundcloud.com https://widgets.resy.com https://www.facebook.com https://www.google.com https://www.googletagmanager.com https://www.instagram.com https://www.youtube.com; img-src 'self' data: blob: https: *; media-src 'self' 'unsafe-inline' data: https://*.cloudflarestream.com https://crowdriff-video-upload.s3.amazonaws.com https://embed.videodelivery.net https://media.amnh.org https://videodelivery.net https://www.googletagmanager.com; script-src-elem 'self' 'unsafe-inline' blob: https://pixel.byspotify.com/ping.min.js https://analytics.tiktok.com https://*.abtasty.com https://*.googleapis.com https://addevent.com https://beacon.sojern.com https://*.adsrvr.org https://static.cloudflareinsights.com https://*.videodelivery.net https://*.addevent.com https://ajax.cloudflare.com https://anthro.amnh.org https://by2.uservoice.com https://cdn.knightlab.com https://cdn.syndication.twimg.com https://code.highcharts.com https://code.jquery.com https://collector-2328.tvsquared.com https://connect.facebook.net https://consentag.eu https://data.library.amnh.org https://googleads.g.doubleclick.net https://i.ctnsnet.com https://i.simpli.fi https://maps.googleapis.com https://maps.google.com https://mead2019.sched.com https://platform.instagram.com https://platform.twitter.com https://script.hotjar.com https://ssl.p.jwpcdn.com https://starling.crowdriff.com https://static.hotjar.com https://tagmanager.google.com https://tag.simpli.fi https://tpc.googlesyndication.com https://translate.googleapis.com https://translate.google.com https://translate-pa.googleapis.com https://use.typekit.net https://widget.uservoice.com https://widgets.resy.com https://www.amnh.org https://www.googleadservices.com https://www.google-analytics.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.instagram.com https://www.youtube.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' blob: https://*.abtasty.com data: https://analytics.tiktok.com https://*.abtasty.com https://*.adsrvr.org https://beacon.sojern.com https://static.cloudflareinsights.com https://*.googleapis.com https://*.addevent.com https://ajax.cloudflare.com https://ajax.googleapis.com https://analytics.twitter.com https://anthro.amnh.org https://apis.google.com https://bpb.opendns.com https://cdn.knightlab.com https://cdn.syndication.twimg.com https://cdn.yoochoose.net https://cdnjs.cloudflare.com https://code.highcharts.com https://code.jquery.com https://collector-2328.tvsquared.com https://connect.facebook.net https://consentag.eu https://embed.videodelivery.net https://fullstory.com https://googleads.g.doubleclick.net https://googletagmanager.com https://i.ctnsnet.com https://i.simpli.fi https://maps.google.com https://maps.googleapis.com https://nexus.ensighten.com https://platform.instagram.com https://platform.twitter.com https://region1.google-analytics.com https://rules.quantcount.com https://s.ytimg.com https://script.hotjar.com https://secure.quantserve.com https://ssl.p.jwpcdn.com https://starling.crowdriff.com https://static.ads-twitter.com https://static.hotjar.com https://tag.simpli.fi https://tagmanager.google.com https://tpc.googlesyndication.com https://translate.google.com https://translate.googleapis.com https://use.typekit.net https://useast-www.securly.com https://www.google-analytics.com https://www.google.al https://www.google.ca https://www.google.ch https://www.google.co.in https://www.google.co.tz https://www.google.co.uk https://www.google.com https://www.google.com.ar https://www.google.com.bd https://www.google.de https://www.google.es https://www.google.fr https://www.google.no https://www.google.ro https://www.googleadservices.com https://www.googletagmanager.com https://www.gstatic.com https://www.instagram.com https://www.securly.com https://www.youtube.com; style-src-elem 'self' 'unsafe-inline' https://teddytor.abtasty.com https://www.googletagmanager.com https://cloud.typography.com https://code.jquery.com https://data.library.amnh.org https://fonts.googleapis.com https://platform.twitter.com https://stackpath.bootstrapcdn.com https://starling.crowdriff.com https://tagmanager.google.com https://ton.twimg.com https://translate.googleapis.com https://www.amnh.org https://www.gstatic.com; style-src 'self' 'unsafe-inline' https://cloud.typography.com https://code.jquery.com https://fonts.googleapis.com https://p.typekit.net https://platform.twitter.com https://starling.crowdriff.com https://ton.twimg.com https://translate.googleapis.com https://use.typekit.net; manifest-src 'self'; worker-src blob: 'self'; object-src https://www.youtube.com; report-to report-uri-amnh-csp-endpoint; report-uri https://amnh.report-uri.com/r/t/csp/enforce |
access-control-allow-origin: |
* |
access-control-allow-methods: |
GET, POST, HEAD |
x-dinosaurs: |
yes |
last-modified: |
Mon, 30 Sep 2024 21:04:17 GMT |
x-web-id: |
2 |
x-cache-maxage: |
1800.000 |
age: |
806 |
via: |
1.1 varnish (Varnish/6.0) |
grace: |
none |
vary: |
Origin,Accept-Encoding |
cache-control: |
public, s-maxage=600, stale-while-revalidate=300, stale-if-error=300 |
x-cache: |
HIT |
x-cache-hits: |
165 |
x-cache-age: |
806 |
location: |
|
cf-cache-status: |
DYNAMIC |
server: |
cloudflare |
cf-ray: |
8cb73dcfca670b43-AMS |