content-type: |
text/html; charset=utf-8 |
cache-control: |
private, no-cache, no-store, max-age=0, must-revalidate |
content-security-policy: |
upgrade-insecure-requests;default-src 'nonce-6d7b1bc16936d479645d281b8f21cdec' 'self' 'nonce-de5a477138de56ffdae2664ca5b9cb25' 'unsafe-eval' 'unsafe-inline' *.bing.com *.bedbathandbeyond.com *.bedbathandbeyond.ca *.clarity.ms *.ostkcdn.com *.ostkcdn.com google.com *.google.com *.google.ca *.google-analytics.com *.google.co.uk *.googlesyndication.com *.googletagmanager.com *.newrelic.com *.nr-data.net bam.nr-data.net *.tiqcdn.com *.facebook.net *.facebook.com *.akamaihd.net *.doubleclick.net *.appboycdn.com *.braze.com *.creativecdn.com *.3gl.net cm.adform.net ih.adscale.de visitor.omnitagjs.com pixel.advertising.com ib.adnxs.com ice.360yield.com dsum-sec.casalemedia.com pixel.rubiconproject.com hbx.media.net cm.mgid.com onetag-sys.com us-u.openx.net sync.outbrain.com simage2.pubmatic.com bh.contextweb.com s.seedtag.com match.sharethrough.com s.ad.smaato.net us.ck-ie.com ce.lijit.com sync.taboola.com eb2.3lift.com s-cs.rmp.rakuten.com dot.wp.pl ad.yieldlab.net ads.yieldmo.com t.visx.net ssc-cms.33across.com pixel.s3xified.com inv-nets.admixer.net sync.connectad.io sync.e-planning.net csync.loopme.me adn.caprofitx.com sync.addlv.smt.docomo.ne.jp sync.1rx.io ssp-csync.smartadserver.com csync.smilewanted.com sync.teads.tv rt.udmserve.net sync.console.adtarget.com.tr visitor.omnitagjs.com rtb.gumgum.com dot.wp.pl cm-exchange.toast.com ad.as.amanad.adtdp.com sync.bidence.net cs.gssprt.jp sp.gmossp-sp.jp analytics.ad.daum.net s-cs.send.microad.jp mixer.mobon.net tg.socdm.com sync.ad-stir.com;connect-src 'self' *.overstock.com *.overstock.ca *.bedbathandbeyond.com *.bedbathandbeyond.ca *.bing.com *.clarity.ms *.ostkcdn.com *.ostkcdn.com google.com *.google.com *.google-analytics.com *.google.co.uk *.google.ca *.googletagmanager.com *.googlesyndication.com *.newrelic.com *.nr-data.net bam.nr-data.net *.tiqcdn.com *.tealiumiq.com *.facebook.net *.facebook.com *.akamaihd.net *.akstat.io *.doubleclick.net *.go-mpulse.net *.appboycdn.com *.creativecdn.com *.braze.com *.paypal.com *.3gl.net *.evergage.com cm.adform.net ih.adscale.de visitor.omnitagjs.com pixel.advertising.com ib.adnxs.com ice.360yield.com dsum-sec.casalemedia.com pixel.rubiconproject.com hbx.media.net cm.mgid.com onetag-sys.com us-u.openx.net sync.outbrain.com simage2.pubmatic.com bh.contextweb.com s.seedtag.com match.sharethrough.com s.ad.smaato.net us.ck-ie.com ce.lijit.com sync.taboola.com eb2.3lift.com s-cs.rmp.rakuten.com dot.wp.pl ad.yieldlab.net ads.yieldmo.com t.visx.net ssc-cms.33across.com pixel.s3xified.com inv-nets.admixer.net sync.connectad.io sync.e-planning.net csync.loopme.me adn.caprofitx.com sync.addlv.smt.docomo.ne.jp sync.1rx.io ssp-csync.smartadserver.com csync.smilewanted.com sync.teads.tv rt.udmserve.net sync.console.adtarget.com.tr visitor.omnitagjs.com rtb.gumgum.com dot.wp.pl cm-exchange.toast.com ad.as.amanad.adtdp.com sync.bidence.net cs.gssprt.jp sp.gmossp-sp.jp analytics.ad.daum.net s-cs.send.microad.jp mixer.mobon.net tg.socdm.com sync.ad-stir.com;img-src 'self' data: blob: *.ostkcdn.com *.overstock.com *.overstock.ca *.bedbathandbeyond.com *.bedbathandbeyond.ca *.bing.com *.clarity.ms *.cloudinary.com *.facebook.com ytimg.com *.ytimg.com *.google-analytics.com google.com *.google.com *.google.co.uk *.google.ca *.google.pl *.google.es *.google.com.ph *.google.com.pr *.google.co.ma *.google.co.in *.google.co.id *.google.am *.google.tt *.google.com.ng *.google.com.au *.google.it *.google.lv *.google.de *.google.lu *.google.nl *.google.com.br *.google.vg *.google.lk *.google.com.pk *.google.co.za *.google.ie *.google.rw *.google.com.eg *.google.com.vn *.gstatic.com *.google.com.hk *.google.com.et *.google.vg *.googlesyndication.com *.googletagmanager.com googleads.g.doubleclick.com *.akamaihd.net *.doubleclick.net appboy-images.com braze-images.com *.cdn.braze.eu *.appboycdn.com *.creativecdn.com *.braze.com *.paypal.com *.3gl.net cm.adform.net ih.adscale.de visitor.omnitagjs.com pixel.advertising.com ib.adnxs.com ice.360yield.com dsum-sec.casalemedia.com pixel.rubiconproject.com hbx.media.net cm.mgid.com 1ybaxwjk.micpn.com onetag-sys.com us-u.openx.net sync.outbrain.com simage2.pubmatic.com bh.contextweb.com s.seedtag.com match.sharethrough.com s.ad.smaato.net us.ck-ie.com ce.lijit.com sync.taboola.com eb2.3lift.com s-cs.rmp.rakuten.com dot.wp.pl ad.yieldlab.net ads.yieldmo.com t.visx.net ssc-cms.33across.com pixel.s3xified.com inv-nets.admixer.net sync.connectad.io sync.e-planning.net csync.loopme.me adn.caprofitx.com sync.addlv.smt.docomo.ne.jp sync.1rx.io ssp-csync.smartadserver.com csync.smilewanted.com sync.teads.tv rt.udmserve.net sync.console.adtarget.com.tr visitor.omnitagjs.com rtb.gumgum.com dot.wp.pl cm-exchange.toast.com ad.as.amanad.adtdp.com sync.bidence.net cs.gssprt.jp sp.gmossp-sp.jp analytics.ad.daum.net s-cs.send.microad.jp mixer.mobon.net tg.socdm.com sync.ad-stir.comscript-src-elem 'self' 'unsafe-inline' *.overstock.com *.overstock.ca *.bedbathandbeyond.com *.bedbathandbeyond.ca *.bing.com *.clarity.ms *.ostkcdn.com *.ostkcdn.com google.com *.google.com *.google-analytics.com *.google.co.uk *.googletagmanager.com *.googlesyndication.com *.googleadservices.com *.gstatic.com *.newrelic.com *.nr-data.net *.tiqcdn.com *.facebook.net *.facebook.com *.akamaihd.net *.doubleclick.net *.go-mpulse.net *.appboycdn.com *.creativecdn.com *.braze.com *.paypal.com *.3gl.net cm.adform.net ih.adscale.de visitor.omnitagjs.com pixel.advertising.com ib.adnxs.com ice.360yield.com dsum-sec.casalemedia.com pixel.rubiconproject.com hbx.media.net cm.mgid.com 1ybaxwjk.micpn.com onetag-sys.com us-u.openx.net sync.outbrain.com simage2.pubmatic.com bh.contextweb.com s.seedtag.com match.sharethrough.com s.ad.smaato.net us.ck-ie.com ce.lijit.com sync.taboola.com eb2.3lift.com s-cs.rmp.rakuten.com dot.wp.pl ad.yieldlab.net ads.yieldmo.com t.visx.net ssc-cms.33across.com pixel.s3xified.com inv-nets.admixer.net sync.connectad.io sync.e-planning.net csync.loopme.me adn.caprofitx.com sync.addlv.smt.docomo.ne.jp sync.1rx.io ssp-csync.smartadserver.com csync.smilewanted.com sync.teads.tv rt.udmserve.net sync.console.adtarget.com.tr visitor.omnitagjs.com rtb.gumgum.com dot.wp.pl cm-exchange.toast.com ad.as.amanad.adtdp.com sync.bidence.net cs.gssprt.jp sp.gmossp-sp.jp analytics.ad.daum.net s-cs.send.microad.jp mixer.mobon.net tg.socdm.com sync.ad-stir.com;script-src 'self' 'unsafe-inline' 'unsafe-eval' *.overstock.com *.overstock.ca *.bedbathandbeyond.com *.bedbathandbeyond.ca *.bing.com *.clarity.ms *.ostkcdn.com *.ostkcdn.com google.com *.google.com *.google-analytics.com *.google.co.uk *.gstatic.com *.googlesyndication.com *.googletagmanager.com *.googleadservices.com *.newrelic.com *.nr-data.net *.evgnet.com *.tiqcdn.com *.facebook.net *.facebook.com *.akamaihd.net *.doubleclick.net *.go-mpulse.net *.appboycdn.com *.creativecdn.com *.braze.com *.3gl.net cm.adform.net ih.adscale.de visitor.omnitagjs.com pixel.advertising.com ib.adnxs.com ice.360yield.com dsum-sec.casalemedia.com pixel.rubiconproject.com hbx.media.net cm.mgid.com 1ybaxwjk.micpn.com onetag-sys.com us-u.openx.net sync.outbrain.com simage2.pubmatic.com bh.contextweb.com s.seedtag.com match.sharethrough.com s.ad.smaato.net us.ck-ie.com ce.lijit.com sync.taboola.com eb2.3lift.com s-cs.rmp.rakuten.com dot.wp.pl ad.yieldlab.net ads.yieldmo.com t.visx.net ssc-cms.33across.com pixel.s3xified.com inv-nets.admixer.net sync.connectad.io sync.e-planning.net csync.loopme.me adn.caprofitx.com sync.addlv.smt.docomo.ne.jp sync.1rx.io ssp-csync.smartadserver.com csync.smilewanted.com sync.teads.tv rt.udmserve.net sync.console.adtarget.com.tr visitor.omnitagjs.com rtb.gumgum.com dot.wp.pl cm-exchange.toast.com ad.as.amanad.adtdp.com sync.bidence.net cs.gssprt.jp sp.gmossp-sp.jp analytics.ad.daum.net s-cs.send.microad.jp mixer.mobon.net tg.socdm.com sync.ad-stir.com;script-src-attr 'self' *.overstock.com *.overstock.ca 'unsafe-inline' *.bedbathandbeyond.com *.bedbathandbeyond.ca *.bing.com *.clarity.ms *.ostkcdn.com *.ostkcdn.com google.com *.google.com *.google-analytics.com *.google.co.uk *.googlesyndication.com *.googletagmanager.com *.newrelic.com *.nr-data.net *.tiqcdn.com *.facebook.net *.facebook.com *.akamaihd.net *.doubleclick.net *.appboycdn.com *.creativecdn.com *.3gl.net cm.adform.net ih.adscale.de visitor.omnitagjs.com pixel.advertising.com ib.adnxs.com ice.360yield.com dsum-sec.casalemedia.com pixel.rubiconproject.com hbx.media.net cm.mgid.com onetag-sys.com us-u.openx.net sync.outbrain.com simage2.pubmatic.com bh.contextweb.com s.seedtag.com match.sharethrough.com s.ad.smaato.net us.ck-ie.com ce.lijit.com sync.taboola.com eb2.3lift.com s-cs.rmp.rakuten.com dot.wp.pl ad.yieldlab.net ads.yieldmo.com t.visx.net ssc-cms.33across.com pixel.s3xified.com inv-nets.admixer.net sync.connectad.io sync.e-planning.net csync.loopme.me adn.caprofitx.com sync.addlv.smt.docomo.ne.jp sync.1rx.io ssp-csync.smartadserver.com csync.smilewanted.com sync.teads.tv rt.udmserve.net sync.console.adtarget.com.tr visitor.omnitagjs.com rtb.gumgum.com dot.wp.pl cm-exchange.toast.com ad.as.amanad.adtdp.com sync.bidence.net cs.gssprt.jp sp.gmossp-sp.jp analytics.ad.daum.net s-cs.send.microad.jp mixer.mobon.net tg.socdm.com sync.ad-stir.com;style-src 'self' 'unsafe-inline' *.overstock.com *.overstock.ca *.bedbathandbeyond.com *.bedbathandbeyond.ca *.bing.com *.clarity.ms *.doubleclick.net *.googlesyndication.com *.ostkcdn.com cm.adform.net ih.adscale.de visitor.omnitagjs.com pixel.advertising.com ib.adnxs.com ice.360yield.com dsum-sec.casalemedia.com pixel.rubiconproject.com hbx.media.net cm.mgid.com onetag-sys.com us-u.openx.net sync.outbrain.com simage2.pubmatic.com bh.contextweb.com s.seedtag.com match.sharethrough.com s.ad.smaato.net us.ck-ie.com ce.lijit.com sync.taboola.com eb2.3lift.com s-cs.rmp.rakuten.com dot.wp.pl ad.yieldlab.net ads.yieldmo.com t.visx.net ssc-cms.33across.com pixel.s3xified.com inv-nets.admixer.net sync.connectad.io sync.e-planning.net csync.loopme.me adn.caprofitx.com sync.addlv.smt.docomo.ne.jp sync.1rx.io ssp-csync.smartadserver.com csync.smilewanted.com sync.teads.tv rt.udmserve.net sync.console.adtarget.com.tr visitor.omnitagjs.com rtb.gumgum.com dot.wp.pl cm-exchange.toast.com ad.as.amanad.adtdp.com sync.bidence.net cs.gssprt.jp sp.gmossp-sp.jp analytics.ad.daum.net s-cs.send.microad.jp mixer.mobon.net tg.socdm.com sync.ad-stir.com;font-src 'self' *.overstock.com *.overstock.ca *.bedbathandbeyond.com *.bedbathandbeyond.ca *.gstatic.com *.3gl.net data:;object-src 'none';worker-src 'self' blob: blob *.overstock.com *.overstock.ca *.bedbathandbeyond.com *.bedbathandbeyond.ca *.ostkcdn.com;form-action 'self' *.overstock.com *.overstock.ca *.bedbathandbeyond.com *.bedbathandbeyond.ca *.facebook.com *.3gl.net; frame-src *.paypal.com *.bing.com *.clarity.ms *.facebook.com *.youtube.com google.com *.google.com *.googlesyndication.com *.googletagmanager.com *.overstock.com *.bedbathandbeyond.com *.creativecdn.com *.doubleclick.net *.3gl.net cm.adform.net ih.adscale.de visitor.omnitagjs.com pixel.advertising.com ib.adnxs.com ice.360yield.com dsum-sec.casalemedia.com pixel.rubiconproject.com hbx.media.net cm.mgid.com onetag-sys.com us-u.openx.net sync.outbrain.com simage2.pubmatic.com bh.contextweb.com s.seedtag.com match.sharethrough.com s.ad.smaato.net us.ck-ie.com ce.lijit.com sync.taboola.com eb2.3lift.com s-cs.rmp.rakuten.com dot.wp.pl ad.yieldlab.net ads.yieldmo.com t.visx.net ssc-cms.33across.com pixel.s3xified.com inv-nets.admixer.net sync.connectad.io sync.e-planning.net csync.loopme.me adn.caprofitx.com sync.addlv.smt.docomo.ne.jp sync.1rx.io ssp-csync.smartadserver.com csync.smilewanted.com sync.teads.tv rt.udmserve.net sync.console.adtarget.com.tr visitor.omnitagjs.com rtb.gumgum.com dot.wp.pl cm-exchange.toast.com ad.as.amanad.adtdp.com sync.bidence.net cs.gssprt.jp sp.gmossp-sp.jp analytics.ad.daum.net s-cs.send.microad.jp mixer.mobon.net tg.socdm.com sync.ad-stir.com; report-uri /api/report-content-security-policy-violation |
etag: |
W/"axv00iuehd99nt" |
server: |
nginx/1.24.0 + Phusion Passenger(R) 6.0.19 |
status: |
200 OK |
x-powered-by: |
Phusion Passenger(R) 6.0.19 |
x-akamai-transformed: |
9 - 0 pmb=mRUM,3 |
date: |
Tue, 01 Oct 2024 01:23:02 GMT |
transfer-encoding: |
chunked |
connection: |
close, Transfer-Encoding |
set-cookie: |
_csrf=wPaWlpDo9aX6ph3R-SjAeQUl; Path=/; Secure; HttpOnly,CA_MICRO=1; expires=Sat, 05-Oct-2024 01:23:02 GMT; path=/; secure; SameSite=None,AKA_A2=A; expires=Tue, 01-Oct-2024 02:23:02 GMT; path=/; domain=bedbathandbeyond.ca; secure; HttpOnly,_abck=C4F63F2DCE9F6A311E83EFAA0B3EAD43~-1~YAAQn0d7XBAYhzGSAQAAAXSsRQze1KdahpxL9Cf+tHTwvs05WRUEK+RUmxIOQdi4BEhhr/V0gQb3RVe5GXUV8vPEG1pjnleKUeYnDBa/N6MmrgIRDDSEKCnQ0e0ibrhuWECfy/uentxqgHbYGLlNFrX5t1HdJMiFkQvvsUiM881YT2G7g5aA2mlPXBUROrNX/2eimzWTzLsJaLnEue6c6kGNYzgtIGF39WLtIHtg0KP+n+HzJKazbgjioJHMyGQ5pJKRNiOzs5JgDTpNF3aaJ3m+tDxJYP3JwlQlQvsM0SSdQKfewqq/OUxmPWQA47QSLKmKRmnSy/0t9M/6V/Rzn/TDCHC5E9lX3sVbYHvdqFwuhEeElxih70t+8LzJuigp0BPsgQCeGSm6HE0vqQJAxiIrFlRS1FnXo619J997TPjvPxdWqC8=~-1~-1~-1; Domain=.bedbathandbeyond.ca; Path=/; Expires=Wed, 01 Oct 2025 01:23:02 GMT; Max-Age=31536000; Secure,bm_sz=5C5EA8A0EA98A08F2BCF19961632EF47~YAAQn0d7XBEYhzGSAQAAAXSsRRlSlzgFCeU9foulqlux+yWKn3/y3z14mjMRPc0g9QlHEKXNtcRft0o89vcfCYzqjG5IoAbI+xmyfLBJnEP7p/iqqLfwwhVFlezSJsy6Q9sNO9YGhc+rYZ9N3HkiT2onJsFXeItZd6GPXgmF0gZgYqOnATewA2cPjnUp+o1blmrkiLHV62mmTg4XtqdoT/6ybqhR8bzBvK7tOQ+Xq9KQphAu+crsOIKTM60Wk13dnpA+xwPXQ61vl9Aebe1ghQEou6qHStKpwxwb8pQK/9NkSH6arS1AgWn8noZn7yHmWyW8JeT94RfNq0aLgOU/CUWwUOF2GBgkvI+xcsF3qn9XS8TQlptryulacY+4VF8e9elstPvwaYKjzg==~4539458~3290417; Domain=.bedbathandbeyond.ca; Path=/; Expires=Tue, 01 Oct 2024 05:23:02 GMT; Max-Age=14400 |
server-timing: |
cdn-cache; desc=MISS, edge; dur=347, origin; dur=233, ak_p; desc="1727745782140_1551583135_988708807_57895_11196_3_7_-";dur=1 |
link: |
<https://cdn.evgnet.com>;rel="preconnect", <https://ak1.ostkcdn.com>;rel="preconnect" |
x-ak-client-rtt: |
3 |
strict-transport-security: |
max-age=31536000 |
|