date: |
Wed, 02 Oct 2024 15:05:36 GMT |
content-type: |
text/html |
transfer-encoding: |
chunked |
connection: |
close |
cf-ray: |
8cc5976f7fd096f9-AMS |
cf-cache-status: |
HIT |
accept-ranges: |
bytes |
cache-control: |
public, max-age=3600 |
expires: |
Wed, 02 Oct 2024 16:05:36 GMT |
last-modified: |
Thu, 26 Sep 2024 16:23:03 GMT |
strict-transport-security: |
max-age=31536000 |
vary: |
Accept-Encoding |
via: |
1.1 1bff19813518c379b9a7e50d87c9b2f6.cloudfront.net (CloudFront) |
content-security-policy: |
frame-ancestors 'self' https://app.storyblok.com |
content-security-policy-report-only: |
default-src 'self' *.roche.com *.roche.net *.gene.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.roche.com *.roche.net *.gene.com snap.licdn.com cdn.walkme.com apis.google.com tpc.googlesyndication.com api.html5media.info workdevapp.com cdn-js.net gdata.youtube.com twitter.com geolocation.onetrust.com api.flickr.com graph.facebook.com sharecdn.social9.com maps.googleapis.com use.typekit.com use.typekit.net munchkin.marketo.net img.en25.com w.likebtn.com cdn.mathjax.org sadmin.brightcove.com cdnjs.cloudflare.com releases.flowplayer.org script.crazyegg.com wi.likebtn.com pepperglobal.com analytics.twitter.com cdn.blueconic.net connect.facebook.net fullstory.com script.hotjar.com gnntch.blueconic.net rules.quantcount.com secure.quantserve.com static.hotjar.com www.youtube.com www.googletagmanager.com www.google-analytics.com google-analytics.com *.gstatic.com static.ads-twitter.com sjs.bizographics.com *.linkedin.com www.google.com w.soundcloud.com s.ytimg.com *.cloudflareaccess.com *.salesforceliveagent.com https://*.roche.com:8080 https://cdnjs.org https://service.force.com/* cdn.cookielaw.org static.cloudflareinsights.com googleads.g.doubleclick.net 7232514.collect.igodigital.com; style-src * 'self' 'unsafe-inline'; img-src * 'self' data:; font-src * 'self' data:; connect-src * 'self'; media-src * 'self' data:; object-src 'self'; child-src 'self' *.roche.com *.roche.net *.gene.com *.facebook.net qpcr.probefinder.com *.force.com *.hotjar.com www.facebook.com www.google.com www.googletagmanager.com www.youtube.com; frame-src 'self' *.roche.com *.roche.net *.gene.com www.youtube.com sites.google.com *.googleapis.com *.cloudfront.net *.facebook.net *.arcot.com live.sagepay.com player.vimeo.com tpc.googlesyndication.com players.brightcove.net qpcr.probefinder.com *.eloqua.com *.hotjar.com *.soundcloud.com *.facebook.com *.google.com *.googletagmanager.com *.youtube-nocookie.com *.youtube.com *.mendeley.com *.force.com https://cdn.walkme.com/*; worker-src 'self' *.roche.com *.roche.net *.gene.com; frame-ancestors 'self' *.roche.com *.roche.net *.gene.com datastudio.google.com sites.google.com content.bioclinicien.fr connect.facebook.net www.facebook.com s1691.t.eloqua.com *.cloudflareworkers.com; form-action 'self' *.roche.com *.roche.net *.gene.com content.bioclinicien.fr connect.facebook.net www.facebook.com s1691.t.eloqua.com; base-uri 'self' *.roche.com *.roche.net *.gene.com *.secure.roche.com; report-uri https://ayba8dhs.uriports.com/reports/report; report-to default |
expect-staple: |
max-age=86400; includeSubDomains |
feature-policy-report-only: |
geolocation 'none'; camera 'none'; fullscreen *; payment 'self' |
nel: |
{"report_to":"default","max_age":86400,"include_subdomains":true,"failure_fraction": 0.01} |
referrer-policy: |
strict-origin-when-cross-origin |
report-to: |
{"group":"default","max_age":86400,"endpoints":[{"url":"https://ayba8dhs.uriports.com/reports"}],"include_subdomains":true} |
x-amz-cf-id: |
TqjFN6FuK4SnECbHFcOPDSy0HejfqpiMh6pZsY8kVFua1nbVOBFJhQ== |
x-amz-cf-pop: |
BRU50-P1 |
x-amz-id-2: |
NSAYQr+8JHhgTck/OxIQW7hrqn785jvDFyByySpvZw8910yeYlF5uJl4epdUxX9TFW4Cy8PAXEcLuZpHsGW31A== |
x-amz-request-id: |
50AWABZTMPR114PB |
x-amz-server-side-encryption: |
AES256 |
x-cache: |
Miss from cloudfront |
x-content-type-options: |
nosniff |
x-frame-options: |
SAMEORIGIN |
x-xss-protection: |
1; mode=block |
set-cookie: |
__cfruid=b67a1eed1c04d6be795c4b7b7260dd4d16e739c5-1727881536; path=/; domain=.roche.ch; HttpOnly; Secure; SameSite=None,_cfuvid=esTO2Gs6KU6gr_OVepJqo_N8J1yU.HLimGppeqaG2M0-1727881536007-0.0.1.1-604800000; path=/; domain=.roche.ch; HttpOnly; Secure; SameSite=None |
server: |
cloudflare |