cache-control: |
no-cache |
pragma: |
no-cache |
content-type: |
text/html; charset=utf-8 |
expires: |
-1 |
content-security-policy: |
default-src 'self' gateway.moneris.com; script-src 'self' *.googleapis.com *.gstatic.com www.google.com apis.google.com connect.facebook.net ajax.aspnetcdn.com https://www.youtube.com platform.twitter.com https://syndication.twitter.com/ https://s.ytimg.com https://publish.twitter.com *.twimg.com platform.linkedin.com http://platform.stumbleupon.com/1/widgets.js https://*.googletagmanager.com https://cdnjs.cloudflare.com/ https://s3.amazonaws.com/downloads.mailchimp.com/js/mc-validate.js https://fpcanada.us6.list-manage.com/subscribe/post-json unpkg.com cdn.jsdelivr.net gateway.moneris.com/chkt/js/chkt_v1.00.js web-chat.nativechat.com cdn.ampproject.org 'unsafe-inline' 'unsafe-eval'; style-src 'self' *.googleapis.com *.gstatic.com netdna.bootstrapcdn.com kendo.cdn.telerik.com www.google.com platform.twitter.com/css/ *.twimg.com https://cdnjs.cloudflare.com/ https://cdn-images.mailchimp.com/embedcode/ cdn.jsdelivr.net web-chat.nativechat.com 'unsafe-inline'; img-src 'self' *.gstatic.com *.googleapis.com platform.tumblr.com web.facebook.com www.facebook.com www.redditstatic.com www.linkedin.com i.ytimg.com https://syndication.twitter.com https://static.licdn.com/scds/common/u/images/apps/connect/sprites/sprite_connect_v14.png pbs.twimg.com platform.twitter.com/css/ *.twimg.com data: blob: https://*.googletagmanager.com https://s3.ca-central-1.amazonaws.com/fpcanadaimgprofiles/FAPImages/ https://fpcanadaimgprofiles.s3.ca-central-1.amazonaws.com/FAPImages/ *.financialplanningforcanadians.ca financialplanningforcanadians.ca *.fpcanada.ca fpcanada.ca fpcanadaimgprofiles.s3.ca-central-1.amazonaws.com s3.ca-central-1.amazonaws.com online.fpcanada.ca google.ca/ads/ga-audiences www.google.ca/ads/ga-audiences web-chat.nativechat.com; font-src 'self' fonts.gstatic.com kendo.cdn.telerik.com netdna.bootstrapcdn.com data: cdnjs.cloudflare.com cdn.jsdelivr.net; frame-src 'self' www.google.com/ www.youtube.com *.financialplanningforcanadians.ca financialplanningforcanadians.ca *.fpcanada.ca fpcanada.ca gateway.moneris.com td.doubleclick.net web-chat.nativechat.com; connect-src 'self' data: accounts.google.com *.gstatic.com https://*.googletagmanager.com maps.googleapis.com https://www.google-analytics.com/g/collect api.fpcanada.ca blob: analytics.google.com stats.g.doubleclick.net; media-src 'self' data: blob: *.financialplanningforcanadians.ca financialplanningforcanadians.ca *.fpcanada.ca fpcanada.ca; child-src 'self' https://platform.twitter.com/ https://syndication.twitter.com/ https://www.youtube.com/ https://www.youtube-nocookie.com https://player.vimeo.com/ https://w.soundcloud.com/ apis.google.com accounts.google.com staticxx.facebook.com www.facebook.com web.facebook.com badge.stumbleupon.com web-chat.nativechat.com |
cross-origin-embedder-policy: |
unsafe-none |
cross-origin-opener-policy: |
unsafe-none |
cross-origin-resource-policy: |
cross-origin |
permissions-policy: |
accelerometer=(self), ambient-light-sensor=(self), autoplay=(self), battery=(self), camera=(self), cross-origin-isolated=(self), display-capture=(self), document-domain=(self), encrypted-media=(self), execution-while-not-rendered=(self), execution-while-out-of-viewport=(self), fullscreen=(self), geolocation=(self), gyroscope=(self), keyboard-map=(self), magnetometer=(self), microphone=(self), midi=(self), navigation-override=(self), payment=(self), picture-in-picture=(self), publickey-credentials-get=(self), screen-wake-lock=(self), sync-xhr=(self), usb=(self), web-share=(self), xr-spatial-tracking=(self) |
referrer-policy: |
no-referrer-when-downgrade |
strict-transport-security: |
max-age=31536000; includeSubDomains |
x-content-type-options: |
nosniff |
x-frame-options: |
SAMEORIGIN, SAMEORIGIN |
x-xss-protection: |
1; mode=block |
date: |
Wed, 02 Oct 2024 14:44:45 GMT |
content-length: |
74913 |
connection: |
close |
|