date: |
Tue, 01 Oct 2024 12:00:09 GMT |
content-type: |
text/html;charset=utf-8 |
content-length: |
271944 |
connection: |
close |
referrer-policy: |
strict-origin-when-cross-origin |
strict-transport-security: |
max-age=63072000; includeSubDomains; preload |
x-content-type-options: |
nosniff |
x-download-options: |
noopen |
x-frame-options: |
DENY |
x-permitted-cross-domain-policies: |
none |
x-xss-protection: |
1; mode=block |
x-robots-tag: |
index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1 |
access-control-allow-origin: |
* |
cross-origin-opener-policy: |
same-origin |
origin-agent-cluster: |
?1 |
x-dns-prefetch-control: |
off |
content-security-policy: |
base-uri 'self'; default-src 'self'; connect-src 'self' https://cdn.contentful.com https://graphql.contentful.com https://*.abtasty.com https://api.jardiland.com https://*.sentry.io https://api.axept.io https://client.axept.io https://*.algolia.net https://*.algolianet.com https://insights.algolia.io https://auth.jardiland.com https://*.google-analytics.com https://*.analytics.google.com https://www.facebook.com https://www.google.com https://www.google.fr https://*.contentsquare.net https://adservice.google.com https://analytics.google.com https://uberall.com https://locator.uberall.com https://api.mapbox.com https://geo.api.gouv.fr https://googleads.g.doubleclick.net https://stats.g.doubleclick.net https://s3.eu-west-1.amazonaws.com https://storage.googleapis.com https://izanami-api.tooling.invivodigitalfactory.com https://api-adresse.data.gouv.fr https://www.bonial.fr https://www.bonialserviceswidget.de https://trackingapi.bonial.fr https://bonialconnect.com https://analytics.tiktok.com https://maps.googleapis.com https://ct.pinterest.com https://lp.jardiland.com https://lp.gammvert.fr https://www.googleapis.com/geolocation/v1/geolocate 'self' http://localhost:3000; font-src 'self' data: https://bonialconnect.com https://*.uberall.com https://fonts.gstatic.com 'self' https://*.abtasty.com; form-action 'self' https://*.be2bill.com/ https://*.dalenys.com/ https://www.facebook.com; frame-ancestors https://app.contentful.com; frame-src 'self' https://www.facebook.com https://*.doubleclick.net https://tpc.googlesyndication.com https://*.be2bill.com https://*.dalenys.com/ https://ct.pinterest.com https://www.youtube-nocookie.com; img-src 'self' data: blob: https://res.cloudinary.com https://images.ctfassets.net https://axeptio.imgix.net https://www.facebook.com https://connect.facebook.net https://*.contentsquare.net https://ade.googlesyndication.com https://adservice.google.com https://googleads.g.doubleclick.net https://img.youtube.com https://www.google-analytics.com https://www.googletagmanager.com https://www.gstatic.com https://www.google.fr https://www.google.com https://www.google.be https://www.google.it https://www.google.de https://www.google.es https://www.google.ch https://www.google.co.uk https://content-media.bonial.biz https://bonialconnect.com https://publisher-media-old.bonial.biz https://maps.googleapis.com https://publisher-media.bonial.biz https://maps.gstatic.com https://*.uberall.com https://ct.pinterest.com https://favicons.axept.io 'self' https://assets.jardiland.com https://*.abtasty.com; object-src 'none'; script-src 'self' 'unsafe-eval' https://*.abtasty.com https://www.googletagmanager.com https://static.axept.io https://connect.facebook.net https://*.contentsquare.net https://*.dalenys.com https://googleads.g.doubleclick.net https://bonialconnect.com https://maps.googleapis.com https://uberall.com https://*.uberall.com https://tpc.googlesyndication.com https://www.google-analytics.com https://www.googleadservices.com https://www.google.com https://www.google.fr https://cdn.jsdelivr.net/npm/[email protected] https://france.conversiontoolbox.net https://analytics.tiktok.com https://s.pinimg.com https://lp.jardiland.com https://lp.gammvert.fr 'strict-dynamic' 'nonce-aPcOxHz128lBb3EodH6r9A==' 'self' ; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com 'self' https://*.abtasty.com; worker-src blob: |
feature-policy: |
camera 'self'; microphone 'none'; geolocation 'self'; payment 'none' |