date: |
Wed, 09 Oct 2024 12:21:18 GMT |
content-type: |
text/html; charset=utf-8 |
content-length: |
162021 |
connection: |
close |
vary: |
Accept-Encoding |
set-cookie: |
wcc-hech=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1c2VySWQiOiJQaUNEUk5NYThRY1NSekVYa1VUTkEiLCJiYXNrZXRLZXkiOiJQaUNEUk5NYThRY1NSekVYa1VUTkEiLCJ3aXNobGlzdEtleSI6IlBpQ0RSTk1hOFFjU1J6RVhrVVROQSIsImlhdCI6MTcyODQ3NjQ3OH0.bpCIxdubBajUUwXjKS_IM5qYXZ3Q_8yhVXdEDvPldYc; Max-Age=5184000; Domain=.heine.ch; Path=/; Expires=Sun, 08 Dec 2024 12:21:18 GMT; Secure; SameSite=Lax,visitIdChanged=true; Max-Age=1800; Domain=.heine.ch; Path=/; Expires=Wed, 09 Oct 2024 12:51:18 GMT; Secure; SameSite=Lax,visitId=aOB8msWZHXxiHQCKyYq5t; Max-Age=1800; Domain=.heine.ch; Path=/; Expires=Wed, 09 Oct 2024 12:51:18 GMT; Secure; SameSite=Lax,ecc=804; Max-Age=2592000; Domain=.heine.ch; Path=/; Expires=Fri, 08 Nov 2024 12:21:18 GMT; Secure; SameSite=Lax,eccCurrent=804; Max-Age=2592000; Domain=.heine.ch; Path=/; Expires=Fri, 08 Nov 2024 12:21:18 GMT; Secure; SameSite=Lax,eccPaid=804; Max-Age=2592000; Domain=.heine.ch; Path=/; Expires=Fri, 08 Nov 2024 12:21:18 GMT; Secure; SameSite=Lax,trigger=impressionen; Max-Age=1800; Domain=.heine.ch; Path=/; Expires=Wed, 09 Oct 2024 12:51:18 GMT; Secure; SameSite=Lax,optimizelyId=My7FMDgpKLL7hJZh5VFHB; Max-Age=5184000; Domain=.heine.ch; Path=/; Expires=Sun, 08 Dec 2024 12:21:18 GMT; Secure; SameSite=Lax,recoUserId=; Max-Age=0; Domain=.heine.ch; Path=/; Expires=Wed, 09 Oct 2024 12:21:18 GMT; Secure; SameSite=Lax,recoSessionId=HaWw7XJxRcOdqqR8odFNq; Max-Age=604800; Domain=.heine.ch; Path=/; Expires=Wed, 16 Oct 2024 12:21:18 GMT; Secure; SameSite=Lax |
content-security-policy: |
default-src 'self' cdn.wcc.heine.ch https://cdn.wcc.heine.ch/graphql; base-uri 'self' widget.solvemate.com; font-src 'self' cdn.wcc.heine.ch https://fonts.gstatic.com data: widget.solvemate.com *.dixa.io https://*.userwerk.com; img-src * data: https://*.userwerk.com; connect-src 'self' https://cdn.wcc.heine.ch/graphql cdn.wcc.heine.ch cdn.witt.info/ https://images.ctfassets.net te.heine.ch tp.heine.ch wasp.heine.ch wst.heine.ch https://*.analytics.google.com https://*.facebook.com https://*.contentsquare.net https://*.my.onetrust.eu https://*.google-analytics.com https://bat.bing.com eu-witt-gruppe-prod1.mini.snplow.net https://www.google-analytics.com https://www.jsctool.com https://adservice.google.com/pagead/ https://graphql.contentful.com https://privacyportal-eu.onetrust.com https://stats.g.doubleclick.net https://geolocation.onetrust.com https://www.google.com/pagead/ https://googleads.g.doubleclick.net/pagead/ https://*.creativecdn.com https://*.googlesyndication.com https://*.optimizely.com ct.pinterest.com https://jsctool.com checkout-cdn.aboutyou.cloud checkout-cdn.scayle.cloud checkout-v3.wcc.heine.ch https://*.ingest.sentry.io api.solvemate.com widget.solvemate.com relay.solvemate.com *.dixa.io wss://sockets.dixa.io https://*.userwerk.com https://maps.googleapis.com; object-src 'none'; child-src blob: ; script-src * 'unsafe-inline' 'unsafe-eval' https://*.adyen.com https://*.paypal.com blob: *.dixa.io https://*.userwerk.com; style-src 'self' cdn.wcc.heine.ch https://www.googletagmanager.com https://fonts.googleapis.com 'unsafe-inline' d.heine.ch checkout-cdn.aboutyou.cloud checkout-cdn.scayle.cloud https://*.adyen.com https://*.paypal.com blob: widget.solvemate.com *.dixa.io; frame-src 'self' checkout-v3.wcc.heine.ch https://*.awin1.com https://*.criteo.net https://*.criteo.com https://*.adrtx.net https://*.contentsquare.net https://www.googletagmanager.com https://www.facebook.com https://www.youtube.com https://dmp.theadex.com https://5127363.fls.doubleclick.net https://12769738.fls.doubleclick.net https://www.jsctool.com https://creativecdn.com/ https://fledge-eu.creativecdn.com/ https://tbs.tradedoubler.com/ https://survey2.quantilope.com/ https://*.adyen.com https://*.paypal.com https://*.computop-paygate.com blob: *.dixa.io https://*.userwerk.com https://preview.brame-gamification.com/ https://live.brame-gamification.com/; media-src 'self' cdn.wcc.heine.ch cdn.witt.info/ https://images.ctfassets.net https://videos.ctfassets.net https://www.youtube.com https://witt-gruppe-res.cloudinary.com https://res.cloudinary.com *.dixa.io; manifest-src 'self' cdn.wcc.heine.ch *.dixa.io; worker-src 'self' cdn.wcc.heine.ch blob:; form-action 'self' www.facebook.com https://*.userwerk.com; block-all-mixed-content; frame-ancestors 'self' https://app.contentful.com; sandbox allow-scripts allow-forms allow-same-origin allow-top-navigation allow-popups allow-popups-to-escape-sandbox allow-modals; |
x-dns-prefetch-control: |
off |
x-frame-options: |
SAMEORIGIN |
strict-transport-security: |
max-age=15724800; includeSubDomains |
x-content-type-options: |
nosniff |
referrer-policy: |
strict-origin-when-cross-origin |
x-permitted-cross-domain-policies: |
none |
permissions-policy: |
camera=(), microphone=(), geolocation=() |
x-webapp-version: |
d180b4d20380619b1d16a17dc2c7c0d6dc4ca99b |
cache-control: |
private, no-cache, no-store, max-age=0, must-revalidate |
etag: |
"864mltxlzx3gti" |
server-timing: |
total; dur=169.90239; desc="Total Response Time" |
|