accept-ranges: |
bytes |
access-control-allow-origin: |
* |
age: |
374501 |
cache-control: |
public, max-age=0, must-revalidate |
content-disposition: |
inline |
content-length: |
360046 |
content-security-policy: |
base-uri 'none';child-src 'none';connect-src 'self' graph.facebook.com api-js.mixpanel.com client.axept.io www.facebook.com ads.tiktok.com analytics.tiktok.com connect.facebook.net api.axept.io vitals.vercel-insights.com back.whentocop.fr backend.whentocop.fr whentocop-backend-staging.herokuapp.com wtc-comparator-api.herokuapp.com https://wtc-comparator-api-staging.herokuapp.com www.google-analytics.com www.dwin1.com r.skimresources.com t.skimresources.com stockx.pvxt.net electric-vibrant.whentocop.fr backend-staging.whentocop.fr https://region1.google-analytics.com;default-src 'self';font-src 'self' data:;form-action 'self';frame-ancestors 'none';frame-src 'none';img-src 'self' statics.whentocop.fr connect.facebook.net www.facebook.com static.axept.io client.axept.io axeptio.imgix.net favicons.axept.io s3.eu-west-3.amazonaws.com www.google.com www.google-analytics.com www.awin1.com t.skimresources.com p.skimresources.com t0.gstatic.com t1.gstatic.com t2.gstatic.com t3.gstatic.com logs-01.loggly.com electric-vibrant.whentocop.fr backend-staging.whentocop.fr data:;manifest-src 'self';media-src 'self';object-src 'none';prefetch-src 'self';script-src 'self' static.axept.io client.axept.io ads.tiktok.com www.facebook.com analytics.tiktok.com connect.facebook.net vitals.vercel-insights.com api-js.mixpanel.com www.googletagmanager.com www.google-analytics.com www.dwin1.com www.dwin2.com d.impactradius-event.com s.skimresources.com cdn.usefathom.com electric-vibrant.whentocop.fr backend-staging.whentocop.fr 'unsafe-inline';style-src 'self' 'unsafe-inline' www.googletagmanager.com fonts.googleapis.com;worker-src 'self'; |
content-type: |
text/html; charset=utf-8 |
date: |
Sat, 05 Oct 2024 17:20:05 GMT |
etag: |
"6f98db940534cbd665283a9d01e258ea" |
referrer-policy: |
same-origin |
server: |
Vercel |
strict-transport-security: |
max-age=63072000 |
x-content-security-policy: |
base-uri 'none';child-src 'none';connect-src 'self' graph.facebook.com api-js.mixpanel.com client.axept.io www.facebook.com ads.tiktok.com analytics.tiktok.com connect.facebook.net api.axept.io vitals.vercel-insights.com back.whentocop.fr backend.whentocop.fr whentocop-backend-staging.herokuapp.com wtc-comparator-api.herokuapp.com https://wtc-comparator-api-staging.herokuapp.com www.google-analytics.com www.dwin1.com r.skimresources.com t.skimresources.com stockx.pvxt.net electric-vibrant.whentocop.fr backend-staging.whentocop.fr https://region1.google-analytics.com;default-src 'self';font-src 'self' data:;form-action 'self';frame-ancestors 'none';frame-src 'none';img-src 'self' statics.whentocop.fr connect.facebook.net www.facebook.com static.axept.io client.axept.io axeptio.imgix.net favicons.axept.io s3.eu-west-3.amazonaws.com www.google.com www.google-analytics.com www.awin1.com t.skimresources.com p.skimresources.com t0.gstatic.com t1.gstatic.com t2.gstatic.com t3.gstatic.com logs-01.loggly.com electric-vibrant.whentocop.fr backend-staging.whentocop.fr data:;manifest-src 'self';media-src 'self';object-src 'none';prefetch-src 'self';script-src 'self' static.axept.io client.axept.io ads.tiktok.com www.facebook.com analytics.tiktok.com connect.facebook.net vitals.vercel-insights.com api-js.mixpanel.com www.googletagmanager.com www.google-analytics.com www.dwin1.com www.dwin2.com d.impactradius-event.com s.skimresources.com cdn.usefathom.com electric-vibrant.whentocop.fr backend-staging.whentocop.fr 'unsafe-inline';style-src 'self' 'unsafe-inline' www.googletagmanager.com fonts.googleapis.com;worker-src 'self'; |
x-content-type-options: |
nosniff |
x-frame-options: |
SAMEORIGIN |
x-matched-path: |
/ |
x-vercel-cache: |
HIT |
x-vercel-id: |
fra1::9s8cs-1728148805553-54fe71e0216b |
x-webkit-csp: |
base-uri 'none';child-src 'none';connect-src 'self' graph.facebook.com api-js.mixpanel.com client.axept.io www.facebook.com ads.tiktok.com analytics.tiktok.com connect.facebook.net api.axept.io vitals.vercel-insights.com back.whentocop.fr backend.whentocop.fr whentocop-backend-staging.herokuapp.com wtc-comparator-api.herokuapp.com https://wtc-comparator-api-staging.herokuapp.com www.google-analytics.com www.dwin1.com r.skimresources.com t.skimresources.com stockx.pvxt.net electric-vibrant.whentocop.fr backend-staging.whentocop.fr https://region1.google-analytics.com;default-src 'self';font-src 'self' data:;form-action 'self';frame-ancestors 'none';frame-src 'none';img-src 'self' statics.whentocop.fr connect.facebook.net www.facebook.com static.axept.io client.axept.io axeptio.imgix.net favicons.axept.io s3.eu-west-3.amazonaws.com www.google.com www.google-analytics.com www.awin1.com t.skimresources.com p.skimresources.com t0.gstatic.com t1.gstatic.com t2.gstatic.com t3.gstatic.com logs-01.loggly.com electric-vibrant.whentocop.fr backend-staging.whentocop.fr data:;manifest-src 'self';media-src 'self';object-src 'none';prefetch-src 'self';script-src 'self' static.axept.io client.axept.io ads.tiktok.com www.facebook.com analytics.tiktok.com connect.facebook.net vitals.vercel-insights.com api-js.mixpanel.com www.googletagmanager.com www.google-analytics.com www.dwin1.com www.dwin2.com d.impactradius-event.com s.skimresources.com cdn.usefathom.com electric-vibrant.whentocop.fr backend-staging.whentocop.fr 'unsafe-inline';style-src 'self' 'unsafe-inline' www.googletagmanager.com fonts.googleapis.com;worker-src 'self'; |
x-xss-protection: |
1; mode=block |
connection: |
close |