content-type: |
text/html;charset=UTF-8 |
transfer-encoding: |
chunked |
connection: |
close |
date: |
Fri, 11 Oct 2024 21:15:27 GMT |
x-permitted-cross-domain-policies: |
master-only |
referrer-policy: |
no-referrer-when-downgrade |
server: |
nginx |
set-cookie: |
AWSALB=ymDfKCiWwaIMbicgWWBh0wzviSsfIIaPFIkgzzoP4I3jWGQNIj1SJQddAi665CVVRwAi4qkfAxkEXxGJpR3utmfa2qvcM2rvCUWrBbFrbYpX8sJwtrTqV3r75r9K; Expires=Fri, 18 Oct 2024 21:15:27 GMT; Path=/,AWSALBCORS=ymDfKCiWwaIMbicgWWBh0wzviSsfIIaPFIkgzzoP4I3jWGQNIj1SJQddAi665CVVRwAi4qkfAxkEXxGJpR3utmfa2qvcM2rvCUWrBbFrbYpX8sJwtrTqV3r75r9K; Expires=Fri, 18 Oct 2024 21:15:27 GMT; Path=/; SameSite=None; Secure,JSESSIONID=0413A6C7F13310AA0E5D719A37EC898C; Path=/; Secure; HttpOnly,csrf=7KZC8m7pd8UJH9SRS6qrTZzf_3t65RbcasFWOOilNDV4c-0aJReXoDr98NWLqq38sF-50Zr78UXnzkr4Ks6qgQ:AAABkn1vuoY:TKAx5sgwOYKQ5jAov3O1pw,csrf=PyNSWeKJNwGu62DVLVowHmk04fz_OwaEA9J7eUh1ruKbVvD2u6g1n420l-jMvTMert-MNKaVe4fprBHaGSZNIQ:AAABkn1vuoo:Y8PJZvDkCjWBg9z6zGGj7w |
strict-transport-security: |
max-age=31536000, max-age=31536000; includeSubDomains |
x-magnolia-registration: |
Registered |
pragma: |
no-cache |
cache-control: |
no-cache, no-store, must-revalidate, max-age=0 |
expires: |
Thu, 01 Jan 1970 00:00:00 GMT |
content-security-policy: |
default-src * 'unsafe-inline' data:; img-src * 'unsafe-inline' 'unsafe-eval' data:; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.googleadservices.com *.googleapis.com *.google-analytics.com *.googletagmanager.com *.facebook.net *.wpengine.com *.bootstrapcdn.com *.twitter.com *.jquery.com *.fontawesome.com *.google.com *.pinterest.com *.gstatic.com *.uploadlibrary.com *.thomascook.com *.hotjar.com *.imi.chat *.adyen.com *.spendology.io *.webtrends-optimize.com *.azurewebsites.net *.webtrends.com *.optimize.com *.doubleclick.net *.googlesyndication.com *.googletagservices.com *.google.co.uk *.google.com.ua *.direct.ingenico.com cc-cdn.com *.google.nl *.appsflyer.com *.freshchat.com *.btttag.com *.euc-freshbots.ai *.trustpilot.com *.cookielaw.org *.worldline-solutions.com https://embed.typeform.com/next/embed.js https://tgtag.io *.bing.com *.clarity.ms *.tiktok.com https://www.awin1.com *.reflow.tv; style-src 'self' 'unsafe-inline' *.googleapis.com *.gstatic.com *.wpengine.com *.bootstrapcdn.com *.imi.chat *.adyen.com *.spendology.io *.thomascook.com *.google.com *.webtrends-optimize.com *.azurewebsites.net *.webtrends.com *.optimize.com *.freshchat.com *.euc-freshbots.ai *.typeform.com *.typekit.net; font-src 'self' data: *.googleapis.com *.adyen.com *.gstatic.com *.wpengine.com *.imi.chat *.spendology.io *.thomascook.com https://script.hotjar.com *.bootstrapcdn.com *.typekit.net; object-src 'self' *.adyen.com; frame-src 'self' data: *.facebook.com https://platform.twitter.com *.google.com *.hotjar.com *.imi.chat *.adyen.com *.vimeo.com *.youtube.com *.doubleclick.net *.thomascook.io *.youtu.be *.googlesyndication.com https://www.covidchecker.com *.direct.ingenico.com *.modirum.com *.thomascook.com *.freshchat.com *.euc-freshbots.ai *.trustpilot.com *.cardinalcommerce.com *.braintreegateway.com *.braintree-api.com *.rsa3dsauth.co.uk *.arcot.com *.mycardsecure.com *.monzo.com *.capitalone.com *.touch.tech *.wibmo.com *.mncbank.co.id *.typeform.com *.revolut.com *.sparkassen-kreditkarten.de *.swedbank.se *.wlp-acs.com *.rabobank.nl *.tsys.co.uk *.marqeta.com *.viseca.ch *.apata.io *.redsys.es *.edb.com *.asseco-see.hr *.mashreq.com *.cm-cic.com *.monext.fr *.garanti.com.tr; form-action * 'self' 'unsafe-inline' 'unsafe-eval' *.adyen.com *.thomascook.io *.thomascook.com; |
x-xss-protection: |
1; mode=block |
x-frame-options: |
SAMEORIGIN |
x-content-type-options: |
nosniff |
access-control-allow-origin: |
*.thomascook.com |
vary: |
accept-encoding |
x-cache: |
Miss from cloudfront |
via: |
1.1 a4583a5b47f0a64ec35be32f95ac1b46.cloudfront.net (CloudFront) |
x-amz-cf-pop: |
AMS1-P1 |
x-amz-cf-id: |
czOK8w_3YWzi3NEstL2tN_wEGqiwwbW_OqmwFOwyA3UDoCFCgs9E4g== |