date: |
Fri, 04 Oct 2024 16:18:04 GMT |
content-type: |
text/html; charset=utf-8 |
transfer-encoding: |
chunked |
connection: |
close |
referrer-policy: |
no-referrer |
x-dns-prefetch-control: |
off |
x-permitted-cross-domain-policies: |
none |
x-xss-protection: |
0 |
expect-ct: |
max-age=0 |
strict-transport-security: |
max-age=15552000; includeSubDomains |
x-frame-options: |
SAMEORIGIN |
x-amzn-remapped-content-length: |
1028342 |
content-security-policy: |
img-src 'self' *.commercecloud.salesforce.com data: *.cloudflare.com/ajax/libs/twemoji/14.0.2/ *.googleapis.com *.gstatic.com *.lolaliza.com lolaliza.com development-shop-lolaliza.demandware.net staging-shop-lolaliza.demandware.net production-shop-lolaliza.demandware.net *.fitizzy.com *.ftz.io cdn.cookielaw.org *.onetrust.com *.googletagmanager.com *.facebook.com *.facebook.net *.pinimg.com *.pinterest.com *.getflowbox.com *.cloudfront.net *.google-analytics.com *.googleadservices.com *.googlesyndication.com *.google.com *.google.be *.tiktok.com *.doubleclick.net *.dwin1.com *.awin1.com;script-src 'self' 'unsafe-eval' 'unsafe-inline' *.googleapis.com *.fitizzy.com *.ftz.io maps.gstatic.com challenges.cloudflare.com applepay.cdn-apple.com cdn.cookielaw.org/ api.socloz.com api.testing-b.sandbox.socloz.com cdn.cookielaw.org *.onetrust.com *.facebook.com *.facebook.net *.googletagmanager.com *.googleadservices.com *.googlesyndication.com *.google.com *.google.be *.pinterest.com *.getflowbox.com *.pinimg.com *.google-analytics.com *.zdassets.com *.zendesk.com wss://widget-mediator.zopim.com widget-mediator.zopim.com *.tiktok.com *.doubleclick.net https://publickeyservice.keys.adm-services.goog *.dwin1.com *.awin1.com https://runtime.commercecloud.com;connect-src 'self' api.cquotient.com maps.googleapis.com *.commercecloud.salesforce.com development-shop-lolaliza.demandware.net staging-shop-lolaliza.demandware.net production-shop-lolaliza.demandware.net *.lolaliza.com lolaliza.com accelerator-development.mobify-storefront.com accelerator-staging.mobify-storefront.com accelerator-production.mobify-storefront.com cdn.cookielaw.org/ geolocation.onetrust.com/ *.fitizzy.com *.ftz.io cdn.cookielaw.org *.onetrust.com api-eu.mixpanel.com onlinepayments.ccv.eu redirect.jforce.be *.facebook.com *.facebook.net *.pinterest.com maps.gstatic.com *.getflowbox.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.googlesyndication.com *.google.com *.google.be *.zdassets.com *.zendesk.com wss://widget-mediator.zopim.com widget-mediator.zopim.com *.tiktok.com *.doubleclick.net https://publickeyservice.keys.adm-services.goog *.dwin1.com *.awin1.com https://runtime.commercecloud.com;frame-src challenges.cloudflare.com *.lolaliza.com lolaliza.com commondatastorage.googleapis.com player.vimeo.com download-video.akamaized.net www.youtube.com/ cdn.cookielaw.org/ api.socloz.com https://api.testing-b.sandbox.socloz.com *.fitizzy.com *.ftz.io cdn.cookielaw.org *.facebook.com *.facebook.net *.pinterest.com *.getflowbox.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.googlesyndication.com *.google.com *.google.be *.tiktok.com *.doubleclick.net https://publickeyservice.keys.adm-services.goog *.dwin1.com *.awin1.com;media-src 'self' commondatastorage.googleapis.com player.vimeo.com download-video.akamaized.net vod-progressive.akamaized.net *.fitizzy.com *.ftz.io *.facebook.com *.facebook.net *.pinterest.com *.getflowbox.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.googlesyndication.com *.google.com *.google.be *.zdassets.com *.tiktok.com *.doubleclick.net https://publickeyservice.keys.adm-services.goog *.dwin1.com *.awin1.com;upgrade-insecure-requests;default-src 'self';base-uri 'self';block-all-mixed-content;font-src 'self' https: data:;frame-ancestors 'self' https://runtime.commercecloud.com;object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline' |
x-amzn-remapped-connection: |
close |
x-download-options: |
noopen |
x-amz-apigw-id: |
fIgyCF5oDoEEAfA= |
cache-control: |
s-maxage=900 |
x-content-type-options: |
nosniff |
etag: |
W/"fb0f6-UXBOoahWgtrm5GVy3vb7RYGhl+0" |
x-amzn-trace-id: |
Root=1-670014d9-2424fdaa5e69168b53379a02;Parent=2829bb3ae7603be6;Sampled=0;Lineage=1:cd2bbff0:0 |
x-correlation-id: |
a46b9bf2-6e03-41e6-8d0a-beba148dd472 |
x-amzn-remapped-date: |
Fri, 04 Oct 2024 16:16:25 GMT |
x-amzn-requestid: |
26aaca59-39c4-425a-848b-ae6cae983899 |
vary: |
Accept-Encoding |
x-cache: |
Hit from cloudfront |
via: |
1.1 7333604337e68c1ea3a1a85e9b6be668.cloudfront.net (CloudFront) |
x-amz-cf-pop: |
AMS58-P2 |
x-amz-cf-id: |
7U3qsU_E_K5Uy89VY8BLsM-NjIgHsm-iH5sNWtDDTkevKEbGal5zyA== |
age: |
98 |
cf-cache-status: |
DYNAMIC |
server: |
cloudflare |
cf-ray: |
8cd67c5c5e966650-AMS |