connection: |
close |
content-length: |
261244 |
access-control-allow-headers: |
X-Requested-With, X-Prototype-Version |
access-control-allow-origin: |
* |
content-security-policy: |
frame-ancestors self https://s1.ariba.com https://service.ariba.com https://*.punchout2go.com http://*.punchout2go.com http://portal.punchout2go.com https://portal.punchout2go.com https://danafarber.edirx.com http://translate.google.com https://translate.google.com https://s1-2.ariba.com https://*.labcloudinc.com https://*.optimizely.com https://*.sciquest.com http://bchtest.edirx.com https://bchtest.edirx.com https://qa-connect.punchout2go.com http://*.edirx.com https://*.edirx.com http://finpiadev4.tch.harvard.edu:8220 http://finprd.tch.harvard.edu http://bch.edirx.com https://bch.edirx.com http://s1-2.ariba.com http://*.ariba.com https://*.stemcell.com https://youtube.com http://livechatinc.com/ https://qaapp02.xisecurenet.com/ https://*.unimarket.com/ https://*.recapture.io https://*.labfellows.org https://*.labfellowsdemo.com https://*.labfellows.com https://scn.6connex.com/ https://*.elevate.bio https://*.tradecentric.com https://*.chatbot.com https://*.chatbot.io https://*.instagram.com https://wd5-enterprise-services1.workday.com/ccx/ProcurementcXMLReceiver https://td.doubleclick.net; frame-src https://bchtest.edirx.com http://bchtest.edirx.com http://bch.edirx.com https://bch.edirx.com http://danafarber.edirx.com https://danafarber.edirx.com https://s1-2.ariba.com http://s1-2.ariba.com *.brightcove.net *.soundcloud.com *.jotformpro.com *.jotform.com *.jotform2.com *.jotform.net cdn.jotfor.ms vars.hotjar.com disqus.com *.disquscdn.com *.disqus.com *.jotform.io *.livechatinc.com *.jotform.ca *.google.com *.paymetric.com *.xipaynet.com *.xisecurenet.com *.shortstack.com https://www.youtube.com/ *.stemcell.com http://livechatinc.com/ https://calendar.time.ly/ https://platform.twitter.com/ https://syndication.twitter.com/ https://*.unimarket.com/ *.recapture.io *.labfellows.org *.labfellowsdemo.com *.labfellows.com jotpoll.com *.shortstack.page *.jotform.co https://*.instagram.com https://wd5-enterprise-services1.workday.com/ccx/ProcurementcXMLReceiver https://td.doubleclick.net https://*.chatbot.com https://*.chatbot.io https://www.googletagmanager.com; |
content-security-policy-report-only: |
font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com cdn.livechatinc.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com https://connect.punchout2go.com 'self' 'unsafe-inline'; frame-ancestors https://cdn.livechatinc.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.demdex.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com https://cdn.chatbot.com https://*.doubleclick.net https://*.livechatinc.com https://vars.hotjar.com https://*.paymetric.com https://stementorstg.wpengine.com https://calendar.time.ly 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://p.adsymptotic.com https://hm.baidu.com/hm.gif https://bat.bing.com https://c.bing.com https://c.clarity.ms https://*.doubleclick.net/ https://d3cgm8py10hi0z.cloudfront.net/is.gif https://www.facebook.com/privacy_sandbox/ https://www.facebook.com/tr/ https://maps.googleapis.com/maps/ https://maps.gstatic.com/mapfiles/ https://www.google.ca/pagead/ https://www.google.com/pagead/ https://www.google.ca/ads/ https://www.google.com/ads/ https://www.googletagmanager.com/ https://static.kameleoon.com https://px.ads.linkedin.com/ https://cdn.files-text.com/api/accounts/avatars/ https://connect.punchout2go.com https://*.stemcell.com https://t.co https://analytics.twitter.com https://sp.analytics.yahoo.com https://www.linkedin.com/ https://id.rlcdn.com https://aorta.clickagy.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com assets.adobedtm.com *.magento-ds.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.magento-datasolutions.com www.googletagmanager.com https://cdn.recapture.io https://maps.googleapis.com/ https://hm.baidu.com/hm.js https://bat.bing.com https://cdn.chatbot.com https://*.clarity.ms/ https://www.clickcease.com/ https://img.en25.com https://*.doubleclick.net https://connect.facebook.net https://ajax.googleapis.com/ajax/libs/ https://seal.geotrust.com/getgeotrustsslseal geoip-js.com https://*.hotjar.com https://*.livechatinc.com https://snap.licdn.com https://js-agent.newrelic.com https://bam.nr-data.net https://cmp.osano.com https://connect.punchout2go.com/jslib/ https://*.recapture.io/beacon/ https://cdn.recapture.io/sdk/ https://cdn.searchspring.net/intellisuggest/is.min.js https://*.stemcell.com/media/ https://*.twitter.com https://static.ads-twitter.com https://*.xisecurenet.com https://s.yimg.com/wi/ytc.js https://calendar.time.ly https://tags.clickagy.com https://unpkg.com/[email protected]/dist/js/tabulator.min.js https://ws.zoominfo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com *.magento-datasolutions.com *.magento-ds.com *.fontawesome.com https://connect.punchout2go.com/jslib/ https://www.googletagmanager.com/debug/badge.css 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.paypal.com google.com *.google.com api.magento.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com https://app.recapture.io https://bat.bing.com/ https://cdn.chatbot.com https://*.clarity.ms/ https://*.doubleclick.net/ https://geoip-js.com https://www.googleadservices.com https://analytics.google.com/ *.google-analytics.com/ https://fonts.googleapis.com https://www.google.com/pagead/ https://maps.googleapis.com/ https://*.googlesyndication.com/ https://*.hotjar.com https://*.hotjar.io/ https://api.kameleoon.com https://na-data.kameleoon.io https://px.ads.linkedin.com/ https://cdn.linkedin.oribi.io https://*.livechatinc.com https://bam.nr-data.net https://*.api.osano.com/ https://connect.punchout2go.com https://d3peztlk7w3332.cloudfront.net *.searchspring.io *.searchspring.net https://s.yimg.com https://geo-ip.js wss://*.hotjar.com https://aorta.clickagy.com https://vc.hotjar.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; |
content-type: |
text/html; charset=UTF-8 |
expires: |
Thu, 03 Oct 2024 04:18:32 GMT |
pragma: |
cache |
traceresponse: |
00-17fa87cae86b3936015cb1f6d4bcc690-4e015371039a75e6-01 |
x-debug-info: |
eyJyZXRyaWVzIjowfQ== |
x-frame-options: |
SAMEORIGIN |
x-platform-server: |
i-01321b1a1f5cfd7f1, i-01321b1a1f5cfd7f1 |
accept-ranges: |
bytes |
date: |
Wed, 02 Oct 2024 11:41:47 GMT |
age: |
26594 |
x-served-by: |
cache-bfi-kbfi7400087-BFI, cache-ams2100114-AMS |
x-cache: |
HIT, HIT |
x-cache-hits: |
3, 1 |
cache-control: |
no-store, no-cache, must-revalidate, max-age=0 |
vary: |
Accept-Encoding,Cookie |
x-content-type-options: |
nosniff |
permissions-policy: |
geolocation=*, browsing-topics=() |
strict-transport-security: |
max-age=31536000; includeSubDomains; preload |