date: |
Mon, 07 Oct 2024 22:22:53 GMT |
content-type: |
text/html; charset=utf-8 |
content-length: |
33124 |
connection: |
close |
cache-control: |
no-cache, no-store |
pragma: |
no-cache |
set-cookie: |
.AspNetCore.Antiforgery.qoo-dYBtBeg=CfDJ8BTpxF7ioBlFjbQYXB6Z2cj2ynNYQEAGMxOTv7Kz8ueaDdf2ItZgOX0QG49xXiP6Ma0fvz9kdBHvEienvhtH5lP3tdCW5jAQ9y4-q6oZXZazfD5ClVTg4Ml9BQOeqfgqUj_7rmhfy_o3rBYCZ7ho6dQ; path=/; secure; samesite=strict; httponly |
strict-transport-security: |
max-age=31536000 |
x-frame-options: |
SAMEORIGIN |
x-xss-protection: |
1; mode=block |
x-content-type-options: |
nosniff |
x-download-options: |
noopen |
referrer-policy: |
strict-origin-when-cross-origin |
x-permitted-cross-domain-policies: |
none |
permissions-policy: |
accelerometer=*, autoplay=*, camera=*, cross-origin-isolated=*, encrypted-media=*, fullscreen=*, geolocation=*, gyroscope=*, magnetometer=*, microphone=*, midi=(), payment=*, picture-in-picture=*, publickey-credentials-get=*, screen-wake-lock=(), sync-xhr=*, usb=(), xr-spatial-tracking=self, clipboard-read=*, clipboard-write=* |
content-security-policy: |
connect-src 'self' *.icordis.be *.lcp.be burgerprofiel.vlaanderen.be wss://authenticatie.vlaanderen.be wss://prod.widgets.burgerprofiel.vlaanderen.be https://prod.widgets.burgerprofiel.vlaanderen.be wss://prod.contactapi.uat-vlaanderen.be https://prod.contactapi.uat-vlaanderen.be https://contactapi.vlaanderen.be *.burgerprofiel.be geoserver.gis.cloud.mow.vlaanderen.be api.gipod.vlaanderen.be geo.api.vlaanderen.be *.vrijwilligerswerk.be *.algolianet.com *.algolia.net vrijwilligerswerk.be *.enviso.io *.adyen.com *.timeblockr.com *.api.timeblockr.cloud *.google-analytics.com *.googletagmanager.com stats.g.doubleclick.net *.analytics.google.com *.readspeaker.com *.giveaday.be https://apps.ticketmatic.com toegankelijk.vlaanderen.be *.googleapis.com *.topdesk.net *.hcaptcha.com *.matomo.cloud https://geoserver.gis.cloud.mow.vlaanderen.be; font-src 'self' *.icordis.be *.lcp.be https://ui.vlaanderen.be https://dij151upo6vad.cloudfront.net *.gstatic.com *.curator.io *.vrijwilligerswerk.be vrijwilligerswerk.be *.widget.enviso.io *.enviso.io *.timeblockr.com *.api.timeblockr.cloud *.readspeaker.com data: https://fonts.googleapis.com https://fonts.gstatic.com https://kit-pro.fontawesome.com https://apps.ticketmatic.com *.typekit.net https://fonts.gstatic.com *.googleapis.com *.topdesk.net; frame-src 'self' *.icordis.be *.lcp.be notfound-static.fwebservices.be stratenplan.heist-op-den-berg.be *.iamfas.belgium.be https://prod.widgets.burgerprofiel.vlaanderen.be https://prod.frontend.burgerprofiel.vlaanderen.be https://authenticatie.vlaanderen.be https://idp.iamfas.belgium.be https://www.openstreetmap.org https://umap.openstreetmap.fr *.youtube.com youtu.be www.youtube.com *.curator.io *.vimeo.com *.vrijwilligerswerk.be *.algolianet.com vrijwilligerswerk.be *.algolia.net *.gift2give.be maps.geopunt.be *.maps.geopunt.be *.api.vlaanderen.be *.vlaanderen.be *.geopunt.be *.bizlocator.be *.spotto.be *.jobsolutions.be *.3p.eu *.widget.enviso.io *.enviso.io *.adyen.com *.timeblockr.com *.api.timeblockr.cloud *.arcg.is arcg.is *.maps.arcgis.com *.arcgis.com *.google.com https://calendar.google.com plugin.routeyou.com www3.sport.vlaanderen *.tableau.com *.topdesk.net *.hcaptcha.com; img-src 'self' *.icordis.be *.lcp.be data: *.amazonaws.com https://prod.widgets.burgerprofiel.vlaanderen.be https://prod.widgetconfigservice.burgerprofiel.vlaanderen.be data: *.osm.be *.informatievlaanderen.be *.geopunt.be *.tile.openstreetmap.org https://geo.api.vlaanderen.be geoserver.gis.cloud.mow.vlaanderen.be api.gipod.vlaanderen.be *.tile.openstreetmap.fr *.gstatic.com *.ytimg.com *.google.com *.curator.io *.vimeo.com *.vimeocdn.com *.vrijwilligerswerk.be vrijwilligerswerk.be *.algolia.net *.gift2give.be *.jobsolutions.be *.3p.eu *.widget.enviso.io *.enviso.io *.adyen.com *.timeblockr.com *.api.timeblockr.cloud *.google-analytics.com *.googletagmanager.com *.google.be *.uitdatabank.be udb-media.imgix.net udb2-media.imgix.net images-prod-uitdatabank.imgix.net *.westtoer.be *.west-vlaanderen.be *.cloudfront.net *.giveaday.be openfed.github.io https://apps.ticketmatic.com toegankelijk.vlaanderen.be https://openfed.github.io *.tableau.com *.googleapis.com *.topdesk.net https://squizlabs.github.io *.matomo.cloud https://geoserver.gis.cloud.mow.vlaanderen.be; script-src 'self' 'unsafe-inline' *.icordis.be *.lcp.be 'unsafe-eval' https://prod.widgets.burgerprofiel.vlaanderen.be *.vlaanderen.be *.geopunt.be *.youtube.com *.curator.io *.vrijwilligerswerk.be *.algolianet.com vrijwilligerswerk.be *.algolia.net *.vlaanderen.be *.jobsolutions.be *.3p.eu *.widget.enviso.io *.enviso.io *.adyen.com *.timeblockr.com *.api.timeblockr.cloud *.google-analytics.com *.googletagmanager.com *.arcg.is arcg.is *.maps.arcgis.com *.arcgis.com *.readspeaker.com https://geo.api.vlaanderen.be *.giveaday.be openfed.github.io https://apps.ticketmatic.com toegankelijk.vlaanderen.be https://openfed.github.io *.tableau.com *.googleapis.com *.topdesk.net *.hcaptcha.com https://squizlabs.github.io cdn.matomo.cloud *.vlaanderen.be; worker-src 'self' www.heist-op-den-berg.be *.icordis.be *.lcp.be https://prod.widgets.burgerprofiel.vlaanderen.be *.curator.io *.enviso.io *.adyen.com *.api.timeblockr.cloud https://apps.ticketmatic.com *.topdesk.net; frame-ancestors 'self' https://stats.lcp.be *.enviso.io *.adyen.com https://stats.lcp.be *.topdesk.net; style-src 'self' 'unsafe-inline' *.icordis.be *.lcp.be www.heist-op-den-berg.be fonts.googleapis.com *.vrijwilligerswerk.be vrijwilligerswerk.be *.algolia.net *.widget.enviso.io *.enviso.io *.timeblockr.com *.api.timeblockr.cloud *.readspeaker.com *.giveaday.be *.googleapis.com https://kit-pro.fontawesome.com fonts.googleapis.com openfed.github.io toegankelijk.vlaanderen.be *.typekit.net https://openfed.github.io *.googleapis.com *.topdesk.net https://squizlabs.github.io; object-src *.api.timeblockr.cloud; report-uri /report-csp-violation |
|