date: |
Mon, 07 Oct 2024 21:54:07 GMT |
content-type: |
text/html; charset=UTF-8 |
transfer-encoding: |
chunked |
connection: |
close |
cf-ray: |
8cf120b9ba7b6625-AMS |
cf-cache-status: |
DYNAMIC |
cache-control: |
no-store, no-cache, must-revalidate |
expires: |
Thu, 19 Nov 1981 08:52:00 GMT |
set-cookie: |
PHPSESSID=pc91t980crhmpdfisofo7rshe3; expires=Tue, 08 Oct 2024 01:54:07 GMT; Max-Age=14400; path=/; secure;HttpOnly;Secure,bandeau_deroulant=ouvert; expires=Mon, 14 Oct 2024 21:54:07 GMT; Max-Age=604800; path=/;HttpOnly;Secure,__cflb=02DiuEu5gjAGarxjbVW5VzLSJvUqDu9gPAyngqaYVZQnu; SameSite=Lax; path=/; expires=Tue, 08-Oct-24 09:54:07 GMT; HttpOnly,__cfwaitingroom=Chg4NjRsYzViVG1zaWdqdkJTYTJjRmp3PT0SkAJ6QkhEQ1BtdXMxbTdWS0xjY01SSVBEcnhmd3duTDdaOUVPRUtYV1JoK0lZZjFkUU53a05GdFRDa3JDYlRPMVdTOXZmc3JmSmcwRzBodHJhbGhDOGorNnY3M1lhNUE4bUh2MW4rSVJVWGkrT0MzR29DM2NQWDhRWGIzMGdHTWdyR0tmRjIveU1ETTA3K3NleFVkRkNvQmUvUkRYK1NFQ3IyZXRSYjVuUUprdDhHQTBKeWtTNVlzTlg4K0hXeGpVN2lBQys1Wm5Sc2dxS0xFY2FFR3J4WDdjWnoyZ1JhbkhDOHlxZGV0QU5EaW9Fbmt0c0gvOUUrVkFsTUlYNzNSM0VBRExDNzdaU0x3Z3JnQWtqNw%3D%3D; Domain=www.aucoffre.com; Path=/; Expires=Mon, 07 Oct 2024 21:59:07 GMT; HttpOnly; SameSite=Lax |
strict-transport-security: |
max-age=31536000 |
vary: |
Accept-Encoding |
pragma: |
no-cache |
content-security-policy: |
block-all-mixed-content; upgrade-insecure-requests; child-src app.hubspot.com bid.g.doubleclick.net s.tradingview.com widget.trustpilot.com www.google.com www.googletagmanager.com www.youtube.com; connect-src 'self' adservice.google.com api.axept.io api.hubapi.com api.hubspot.com *.contentsquare.net cdn.cookielaw.org client.axept.io cta-service-cms2.hubspot.com forms.hubspot.com forms.hsforms.com googleads.g.doubleclick.net graph.facebook.com hubspot-forms-static-embed.s3.amazonaws.com js.checkout.com k-eu1.az.contentsquare.net pagead2.googlesyndication.com privacyportal-de.onetrust.com region1.google-analytics.com region1.analytics.google.com s.yimg.com settings.luckyorange.net stats.g.doubleclick.net support.jegtheme.com www.facebook.com www.googleadservices.com www.google-analytics.com www.google.com cdn.jsdelivr.net auth.photo.gallery; default-src 'self' 'unsafe-eval' 'unsafe-inline' adservice.google.com api.hubapi.com api.hubspot.com app.hubspot.com bat.bing.com brigstoneapp.com cdn.cookielaw.org champy.xtz.ch chrome-extension connect.facebook.net data: fonts.googleapis.com fonts.gstatic.com forms.hsforms.com geolocation.onetrust.com googleads.g.doubleclick.net hublosk.com js.hs-analytics.net js.hs-banner.com js.hs-scripts.com js.hsadspixel.net js.hsforms.net js.hubspotfeedback.com js.usemessages.com jullyambery.net pagead2.googlesyndication.com privacyportal-de.onetrust.com s.tradingview.com s.yimg.com s3.tradingview.com settings.luckyorange.net sp.analytics.yahoo.com ssl.google-analytics.com ssl.luckyorange.com static.aucoffre.com stats.g.doubleclick.net track.hubspot.com widget.trustpilot.com www.facebook.com www.google-analytics.com www.google.com www.google.fr www.googleadservices.com www.googletagmanager.com www.gstatic.com www.youtube-nocookie.com www.youtube.com; font-src 'self' data: fonts.gstatic.com github.com static3.avast.com; frame-src 'self' accounts.google.com app.hubspot.com app.livestorm.co bid.g.doubleclick.net content-people.googleapis.com csxd.aucoffre.com csxd.contentsquare.net csxd.loretlargent.info csxd.veravalor.com docs.google.com embed.acast.com forms.hsforms.com js.checkout.com lookerstudio.google.com s.tradingview.com td.doubleclick.net widget.trustpilot.com www.facebook.com www.google.com www.tradingview.com www.youtube.com; img-src 'self' axeptio.imgix.net bat.bing.com *.contentsquare.net cdn.cookielaw.org data: blob: favicons.axept.io forms.hsforms.com forms-na1.hsforms.com *.gstatic.com googleads.g.doubleclick.net i.ytimg.com pagead2.googlesyndication.com perf-na1.hsforms.com secure.gravatar.com sp.analytics.yahoo.com static.aucoffre.com stats.g.doubleclick.net track.hubspot.com translate.google.com www.aucoffre.com www.facebook.com www.google-analytics.com www.google.be www.google.ca www.google.ch www.google.ci www.google.co.ma www.google.co.uk www.google.com www.google.com.pe www.google.cz www.google.es www.google.fr www.google.hu www.google.nl www.google.no www.google.pt www.googleadservices.com www.googletagmanager.com www.gstatic.com; manifest-src 'self'; media-src 'self' static.aucoffre.com; object-src 'self'; script-src-attr 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' blob: apis.google.com app.contentsquare.com appleid.cdn-apple.com bat.bing.com cdn.checkout.com cdn.cookielaw.org code.jquery.com connect.facebook.net data1.acomyl.com data: data1.jenemar.com data1.krouche.com fevoki.wejekihota.com fidoapi.com forms.hsforms.com geolocation.onetrust.com googleads.g.doubleclick.net js.hs-analytics.net js.hs-banner.com js.hs-scripts.com js.hsadspixel.net js.hsforms.net js.hsleadflows.net js.hubspot.com js.hubspotfeedback.com js.usemessages.com pagead2.googlesyndication.com s.yimg.com s3.tradingview.com ssl.google-analytics.com ssl.luckyorange.com static.axept.io stats.g.doubleclick.net tally.so t.contentsquare.net widget.trustpilot.com www.google-analytics.com www.google.com www.googleadservices.com www.googletagmanager.com www.gstatic.com www.youtube.com cdn.jsdelivr.net; script-src 'self' 'unsafe-eval' 'unsafe-inline' apis.google.com app.contentsquare.com appleid.cdn-apple.com bat.bing.com cdn.checkout.com cdn.cookielaw.org connect.facebook.net data: forms.hsforms.com geolocation.onetrust.com googleads.g.doubleclick.net js.hs-analytics.net js.hs-banner.com js.hs-scripts.com js.hsadspixel.net js.hsforms.net js.hubspotfeedback.com js.usemessages.com s.yimg.com s3.tradingview.com ssl.google-analytics.com ssl.luckyorange.com stats.g.doubleclick.net t.contentsquare.net widget.trustpilot.com www.aucoffre.com www.google-analytics.com www.google.com www.googleadservices.com www.googletagmanager.com www.gstatic.com www.youtube.com; style-src-attr 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' fonts.googleapis.com cdn.jsdelivr.net; style-src 'self' 'unsafe-eval' 'unsafe-inline' fonts.googleapis.com netdna.bootstrapcdn.com; worker-src 'self' blob: |
x-content-type-options: |
nosniff |
x-frame-options: |
SAMEORIGIN |
server: |
cloudflare |
|