date: |
Wed, 02 Oct 2024 04:24:07 GMT |
content-type: |
text/html; charset=UTF-8 |
transfer-encoding: |
chunked |
connection: |
close |
set-cookie: |
AWSALB=FFmS66IW8PoMYWIIjyy59kSTU6i8NuJDJLmrhzgep1UaBvzbOX5DJTAQBTX9hDyDkdnSBojdZVu9M5QDqdNxLhB8J3l6Zd92kEC3X3wfxF/CYXu9f2Yx5VoNh7lL; Expires=Wed, 09 Oct 2024 04:24:06 GMT; Path=/,AWSALBCORS=FFmS66IW8PoMYWIIjyy59kSTU6i8NuJDJLmrhzgep1UaBvzbOX5DJTAQBTX9hDyDkdnSBojdZVu9M5QDqdNxLhB8J3l6Zd92kEC3X3wfxF/CYXu9f2Yx5VoNh7lL; Expires=Wed, 09 Oct 2024 04:24:06 GMT; Path=/; SameSite=None; Secure |
access-control-max-age: |
1000 |
access-control-allow-headers: |
X-Requested-With, Content-Type, Origin, Authorization, Accept, Client-Security-Token, Accept-Encoding |
access-control-allow-methods: |
POST, GET, OPTIONS, DELETE, PUT |
x-frame-options: |
SAMEORIGIN |
x-xss-protection: |
1; mode=block |
strict-transport-security: |
max-age=31536000; includeSubDomains |
x-content-type-options: |
nosniff |
permissions-policy: |
autoplay=(self), camera=(), browsing-topics=() |
cross-origin-opener-policy: |
same-origin |
cross-origin-resource-policy: |
same-origin |
content-security-policy-report-only: |
default-src 'self' https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com 'unsafe-inline'; img-src 'self' https://images.medaviebc.ca https://images.protectionplusbenefits.ca https://dev.visualwebsiteoptimizer.com https://r2.visualwebsiteoptimizer.com https://forms.hsforms.com https://track.hubspot.com https://media.msg.dotomi.com https://docs.medaviebc.ca https://docs.protectionplusbenefits.ca https://login.dotomi.com https://perf-na1.hsforms.com https://www.google.com https://www.google.ca https://px.ads.linkedin.com https://www.facebook.com https://www.google-analytics.com https://www.googletagmanager.com https://ssl.gstatic.com https://www.gstatic.com https://i.vimeocdn.com https://maps.gstatic.com https://raw.githubusercontent.com https://maps.googleapis.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.ca https://googleads.g.doubleclick.net https://google.com googleads.g.doubleclick.net www.google.com google.com https://ad.doubleclick.net https://ade.googlesyndication.com https://r3.visualwebsiteoptimizer.com https://qc.croixbleue.ca https://sdk.privacy-center.org https://r1.visualwebsiteoptimizer.com https://pluginicons.craft-cdn.com https://s3.us-east-1.amazonaws.com https://www.linkedin.com https://pluginscreenshots.craft-cdn.com https://s3.ca-central-1.amazonaws.com https://forms-na1.hsforms.com data:; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.jsdelivr.net https://pro.fontawesome.com https://googletagmanager.com https://tagmanager.google.com https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com https://pro.fontawesome.com data:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://googletagmanager.com https://tagmanager.google.com https://tagmanager.google.com https://fonts.googleapis.com https://cdn.appdynamics.com https://js.hs-scripts.com https://static.hotjar.com https://dev.visualwebsiteoptimizer.com https://js.stripe.com https://code.jquery.com https://cdn.jsdelivr.net https://stackpath.bootstrapcdn.com https://cdnjs.cloudflare.com https://js.hsbanner.com https://js.hscollectedforms.net https://js.hs-analytics.net https://js.hs-banner.com https://js.hubspot.com https://js.hsleadflows.net https://js.hsadspixel.net https://script.hotjar.com https://s.pinimg.com https://js.adsrvr.org https://www.google-analytics.com https://extend.vimeocdn.com https://googleads.g.doubleclick.net https://ct.pinterest.com https://connect.facebook.net https://snap.licdn.com https://www.vimeo.com https://vimeo.com https://maps.googleapis.com https://maps.googleapis.com https://cdn.datatables.net https://*.googletagmanager.com https://www.googleadservices.com www.googleadservices.com www.google.com google.com www.googletagmanager.com https://www.google.com www.googleadservices.com googleads.g.doubleclick.net https://f.vimeocdn.com https://sdk.privacy-center.org https://api.privacy-center.org https://urldefense.com https://js.hsforms.net blob:; connect-src 'self' https://dev.visualwebsiteoptimizer.com https://www.google-analytics.com https://pdx-col.eum-appdynamics.com https://r2.visualwebsiteoptimizer.com https://forms.hscollectedforms.net https://api.hubapi.com https://cta-service-cms2.hubspot.com https://stats.g.doubleclick.net https://ct.pinterest.com https://forms.hubspot.com https://px.ads.linkedin.com https://resource-navigator-mbc.herokuapp.com https://google.com https://maps.googleapis.com https://api.medavie.bluecross.ca https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.ca https://r3.visualwebsiteoptimizer.com https://pagead2.googlesyndication.com https://api.privacy-center.org https://r1.visualwebsiteoptimizer.com https://feed-proxy.craftcms.com https://api.craftcms.com https://forms.hsforms.com; frame-src 'self' https://*.medaviebc.ca https://js.stripe.com https://td.doubleclick.net https://insight.adsrvr.org https://ct.pinterest.com https://player.vimeo.com https://www.googletagmanager.com https://bid.g.doubleclick.net bid.g.doubleclick.net td.doubleclick.net https://match.adsrvr.org; object-src 'none'; report-uri https://staging.medaviebc.ca/csp-report-endpoint.php |
x-powered-by: |
Craft CMS |
link: |
<https://www.medaviebc.ca/en/>; rel="canonical" |
vary: |
Accept-Encoding |
cf-cache-status: |
DYNAMIC |
server: |
cloudflare |
cf-ray: |
8cc1ebbc5e021e69-AMS |