date: |
Tue, 01 Oct 2024 07:24:34 GMT |
content-type: |
text/html; charset=UTF-8 |
transfer-encoding: |
chunked |
connection: |
close |
accept-ch: |
Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA |
critical-ch: |
Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA |
cross-origin-embedder-policy: |
require-corp |
cross-origin-opener-policy: |
same-origin |
cross-origin-resource-policy: |
same-origin |
origin-agent-cluster: |
?1 |
permissions-policy: |
accelerometer=(),autoplay=(),browsing-topics=(),camera=(),clipboard-read=(),clipboard-write=(),geolocation=(),gyroscope=(),hid=(),interest-cohort=(),magnetometer=(),microphone=(),payment=(),publickey-credentials-get=(),screen-wake-lock=(),serial=(),sync-xhr=(),usb=() |
referrer-policy: |
same-origin |
x-content-options: |
nosniff |
x-frame-options: |
SAMEORIGIN |
cf-mitigated: |
challenge |
cf-chl-out: |
CWv7stGQ/tT/s3gImck2jjOkc6GsoL+V5CJAvqyRhMLHFY4ZQvuQ4juAOZTBXP4JCG7u8cWArDHoEKTL+cQYxRNb6MCKnV4oef22fBIk2EBQ2Iqf2T8aXGC5ip0/B96blvYqVWLXTeEjk52Aek82Cw==$83d4ukWMbtcum9c1p9n+oQ== |
cache-control: |
private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0 |
expires: |
Thu, 01 Jan 1970 00:00:01 GMT |
set-cookie: |
__cf_bm=CzrjaHqxe5H9xASBRfOxlNkTRXD1wzAbwIhQqcHufjc-1727767474-1.0.1.1-kAfWDHT4ls.iEYZp_PtyeOGuUDJXrzK9u699Q3vbtDqGi4BfuXrlnx9gcjh92idUWjKQaDiKRoq1sUeSzYFImw; path=/; expires=Tue, 01-Oct-24 07:54:34 GMT; domain=.drybar.com; HttpOnly; Secure; SameSite=None |
content-security-policy: |
base-uri 'self' 'unsafe-inline'; child-src 'self' http: https: blob: 'unsafe-inline'; connect-src 'self' *.rapidspike.com www.cloudflare.com commerce.adobedtm.com commerce.adobedc.net *.snplow.net dpm.demdex.net api.magento.com commerce.adobe.io performance.typekit.net commerce.adobe.net amcglobal.sc.omtrdc.net www.googletagmanager.com www.googleadservices.com www.google-analytics.com analytics.google.com google.com *.analytics.google.com stats.g.doubleclick.net us-central1-adaptive-growth.cloudfunctions.net app-measurement.com doubleclickbygoogle.com doubleclick.com doubleclick.net googleadservices.com googlesyndication-cn.com googlesyndication.com googletagservices.com *.google.co.uk *.google.fr *.google.de *.google.es *.google.it *.google.nl *.google.be *.google.pl *.google.se *.google.ie *.google.dk *.google.pt *.google.gr *.google.fi *.google.cz *.google.hu *.google.at *.google.ro *.google.sk *.google.si *.google.bg *.google.hr *.google.lt *.google.lv *.google.ee *.google.mt *.google.cy *.google.lu *.google.us *.google.com.au *.google.ca *.google.com.pr *.google.com.mx *.google.co.cr *.google.com https://www.google.com/recaptcha/ *.recaptcha.net vimeo.com *.googlesyndication.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.stripe.network brilliantcollector.com *.brilliantcollector.com *.newrelic.com *.nr-data.net *.algolia.net *.algolia.com *.algolianet.com kustomerapp.com *.kustomerapp.com api.addressy.com ekr.zdassets.com parcellab.com *.parcellab.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com *.kaltura.com rapid-cdn.yottaa.com *.yottaa.net 'unsafe-inline' *.drybar.com *.listrakbi.com *.trustarc.com s.amazon-adsystem.com ara.paa-reporting-advertising.amazon *.algolia.io googletagmanager.com *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net www.facebook.com analytics.tiktok.com; font-src 'self' fonts.gstatic.com use.typekit.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.trustarc.com kustomerapp.com *.kustomerapp.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'unsafe-inline'; form-action 'self' yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'unsafe-inline' www.facebook.com; frame-ancestors 'self' www.gstatic.com stripe.com *.stripe.com; manifest-src 'self' 'unsafe-inline'; media-src 'self' *.adobe.com 'unsafe-inline' *.vimeo.com download-video.akamaized.net blob: data:; object-src 'self' 'unsafe-inline'; style-src 'self' *.adobe.com fonts.googleapis.com parcellab.com *.parcellab.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com *.googleapis.com 'unsafe-inline' cdn.listrakbi.com googletagmanager.com *.googletagmanager.com tagmanager.google.com; worker-src 'unsafe-eval' 'unsafe-inline' 'self' drybar.com/p/1/2; upgrade-insecure-requests; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=3bV6e6F2sZQMnx2WzmJ3VesmTnR2CPLj58cwzS.3kmU-1727767474-1.0.1.1-VxHwyMO2YRR01Bi8T2KCFJAitaOEhVjEl._UADmxpGbPd.imJdOzVEbe9nYWFVILXQMwCqvFofKRpVQMXRoOwPYzjr8HL26RDiS1esfez2fObpU6jlkLqCy9aSQ3FCLiAYhuImuTeVc76JTdCVgX5fufMwBeCiqcRJ0Ou9s1o06.Em7K2cQ039O1hAI8Gbic7xez5R.lcDgLBtuziuKuzw; report-to cf-fklfwlnktnacuigp, frame-src 'self' fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net player.vimeo.com vimeo.com https://www.google.com/recaptcha/ *.recaptcha.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.stripe.network consent-pref.trustarc.com helenoftroy.demdex.net *.kustomer.support *.kustomer.help www.xtento.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'unsafe-inline' www.facebook.com *.googletagmanager.com td.doubleclick.net *.fls.doubleclick.net helpcenter.drybar.com services.listrak.com; img-src 'self' cdnjs.cloudflare.com widgets.magentocommerce.com assets.adobedtm.com dpm.demdex.net cm.everesttech.net *.adobe.com p.typekit.net amcglobal.sc.omtrdc.net www.googletagmanager.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com *.google.co.uk *.google.fr *.google.de *.google.es *.google.it *.google.nl *.google.be *.google.pl *.google.se *.google.ie *.google.dk *.google.pt *.google.gr *.google.fi *.google.cz *.google.hu *.google.at *.google.ro *.google.sk *.google.si *.google.bg *.google.hr *.google.lt *.google.lv *.google.ee *.google.mt *.google.cy *.google.lu *.google.us *.google.com.au *.google.ca *.google.com.pr *.google.com.mx *.google.co.cr *.vimeocdn.com validator.swagger.io *.trustarc.com *.112.2o7.net kustomerapp.com *.kustomerapp.com *.kustomerhostedcontent.com parcellab.com *.parcellab.com www.xtento.com cdn.xtento.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com yotpo-editor-production.s3.amazonaws.com *.kaltura.com data: 'unsafe-inline' www.facebook.com *.listrakbi.com google.com *.google.com www.gstatic.com ssl.gstatic.com googletagmanager.com *.googletagmanager.com fonts.googleapis.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net *.fls.doubleclick.net ad.doubleclick.net ade.googlesyndication.com; script-src 'self' *.rapidspike.com static.cloudflareinsights.com unpkg.com commerce.adobedtm.com assets.adobedtm.com *.adobe.com use.typekit.net commerce.adobe.net amcglobal.sc.omtrdc.net www.googletagmanager.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com magento-recs-sdk.adobe.net vimeo.com www.vimeo.com *.vimeocdn.com player.vimeo.com https://www.google.com/recaptcha/ *.recaptcha.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.stripe.network *.newrelic.com *.nr-data.net *.trustarc.com adobedtm.com *.algolia.net kustomerapp.com *.kustomerapp.com s7.addthis.com parcellab.com *.parcellab.com www.xtento.com cdn.xtento.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com *.kaltura.com rapid-cdn.yottaa.com 'unsafe-inline' 'unsafe-eval' cdn.jsdelivr.net connect.facebook.net analytics.tiktok.com *.analytics.tiktok.com c.amazon-adsystem.com *.listrakbi.com *.listrak.com ajax.googleapis.com *.ajax.googleapis.com googletagmanager.com *.googletagmanager.com tagmanager.google.com www.google.com https://www.gstatic.com/recaptcha/ *.cloudflare.com; worker-src 'unsafe-eval' 'unsafe-inline' 'self' drybar.com/p/2/2; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=5oS6JSS1n63zsyAQYK7ZLCxEyhdGhZgguSZ6HmOASCw-1727767474-1.0.1.1-4O0WYyPv4ZaxKNXYUSpXlVg4CWRsDozb9zjujij26Xx5cvBJYSOMWFHn1eC406wTErwGY3vMf.GxA.GPxLdU7Uh1Bq06MnA.M172xzemcj9ZF6Mw3TehZNlJOxNOqVGwvXaN0..nSj8mDHDkckOpS8P4j7E4T6r_T3BJ7puj1c07ZFyacgVZTOcMRpt0lNVxiTlWK8pWuGocSWT.oL0JRw; report-to cf-zkkcyhepedynwrpv |
report-to: |
{"endpoints":[{"url":"https:\/\/csp-reporting.cloudflare.com\/cdn-cgi\/script_monitor\/report?m=3bV6e6F2sZQMnx2WzmJ3VesmTnR2CPLj58cwzS.3kmU-1727767474-1.0.1.1-VxHwyMO2YRR01Bi8T2KCFJAitaOEhVjEl._UADmxpGbPd.imJdOzVEbe9nYWFVILXQMwCqvFofKRpVQMXRoOwPYzjr8HL26RDiS1esfez2fObpU6jlkLqCy9aSQ3FCLiAYhuImuTeVc76JTdCVgX5fufMwBeCiqcRJ0Ou9s1o06.Em7K2cQ039O1hAI8Gbic7xez5R.lcDgLBtuziuKuzw"}],"group":"cf-fklfwlnktnacuigp","max_age":86400}, {"endpoints":[{"url":"https:\/\/csp-reporting.cloudflare.com\/cdn-cgi\/script_monitor\/report?m=5oS6JSS1n63zsyAQYK7ZLCxEyhdGhZgguSZ6HmOASCw-1727767474-1.0.1.1-4O0WYyPv4ZaxKNXYUSpXlVg4CWRsDozb9zjujij26Xx5cvBJYSOMWFHn1eC406wTErwGY3vMf.GxA.GPxLdU7Uh1Bq06MnA.M172xzemcj9ZF6Mw3TehZNlJOxNOqVGwvXaN0..nSj8mDHDkckOpS8P4j7E4T6r_T3BJ7puj1c07ZFyacgVZTOcMRpt0lNVxiTlWK8pWuGocSWT.oL0JRw"}],"group":"cf-zkkcyhepedynwrpv","max_age":86400} |
server: |
cloudflare |
cf-ray: |
8cbab6bb9cf5b8ba-AMS |
|