connection: |
close |
accept-ranges: |
bytes |
referrer-policy: |
unsafe-url |
x-content-type-options: |
nosniff |
set-cookie: |
JSESSIONID=0CB8D5E71090368195C72A081971E99C; Path=/; Secure; HttpOnly; SameSite=Lax,chumewe_user=89d161eb-8323-4606-b3ab-b471efed0607; Version=1; Domain=.myprotein.it; Path=/; Max-Age=157784630; Expires=Wed, 03-Oct-2029 07:15:42 GMT; SameSite=None; Secure,chumewe_sess=58bcb97e-0ccb-46ce-865d-a18d8e94c8ea; Version=1; Domain=.myprotein.it; Path=/; Max-Age=14400; Expires=Thu, 03-Oct-2024 06:11:52 GMT; SameSite=None; Secure,locale_V6=it_IT; Version=1; Domain=.myprotein.it; Path=/; Max-Age=31556926; Expires=Fri, 03-Oct-2025 08:00:38 GMT; SameSite=None; Secure,csrf_token=04240128286708780020; Version=1; Path=/; SameSite=None; HttpOnly; Secure,NSC_mc_wtsw_efgbvmu_xfctsw_8010_R=1116a3dba5785469f726ba3d8592a6a1ef4a7de0bb7b940093f8a92b25d40acfe4a7bcbb;expires=Thu, 03-Oct-2024 05:11:52 GMT;path=/;secure;httponly |
x-timer: |
S1727921512.064127,VS0,VE14 |
content-type: |
text/html;charset=UTF-8 |
expires: |
Thu, 01 Jan 1970 00:00:00 GMT |
report-to: |
{"group":"report-endpoint","max_age":86400,"endpoints":[{"url":"https://csp.thehut.net/cspReport.txt","priority":1,"weight":1}],"include_subdomains":true} |
cache-control: |
private, max-age=0, no-cache, no-store, must-revalidate |
x-frame-options: |
SAMEORIGIN |
pragma: |
no-cache |
content-security-policy: |
child-src 'self' https://www.googletagmanager.com https://*.liveperson.net https://cdn.appdynamics.com https://*.lpsnmedia.net https://www.facebook.com https://connect.facebook.net https://*.google.com https://widget.trustpilot.com https://*.doubleclick.net https://www.youtube.com https://wb.messengerpeople.com https://static.criteo.net https://*.criteo.com https://tpc.googlesyndication.com https://ct.pinterest.com https://hal9000.redintelligence.net https://*.recaptcha.net https://*.zenaps.com https://*.hotjar.com https://*.akamaihd.net https://*.translate.naver.net https://ln-rules.rewardstyle.com https://tr.snapchat.com https://www.pinterest.com blob: https://*.abtasty.com https://app.qubit.com https://smct.co https://*.smct.co https://smct.io https://*.smct.io https://d2d7do8qaecbru.cloudfront.net; connect-src 'self' https://*.thcdn.com https://*.ingest.sentry.io https://*.pingdom.net https://*.doubleclick.net https://*.google-analytics.com https://capture.trackjs.com https://fp.zenaps.com https://www.facebook.com https://*.google.com https://*.thehut.net https://privacyportal-eu.onetrust.com https://geolocation.onetrust.com https://cdn.cookielaw.org wss://*.liveperson.net https://*.liveperson.net https://*.lpsnmedia.net https://ct.pinterest.com https://*.google.it https://*.akamaihd.net https://*.sciencebehindecommerce.com https://*.hotjar.com wss://*.hotjar.com https://*.googleapis.com https://*.trustpilot.com https://*.pinterest.com https://*.doubleclick.net https://*.bing.com https://connect.facebook.net https://*.baidu.com https://*.parcellab.com https://tr.snapchat.com https://*.contentsquare.net https://*.abtasty.com https://*.qubit.com https://*.qubitproducts.com https://horizon-api.www.myprotein.it https://*.criteo.com https://*.criteo.net https://*.prod.mplat-ppcprotect.com https://*.lunio.ai data: https://sgtm.myprotein.it https://smct.co https://*.smct.co https://smct.io https://*.smct.io https://cognito-identity.eu-west-1.amazonaws.com https://firehose.eu-west-1.amazonaws.com; font-src 'self' data: https://*.thcdn.com https://fp.zenaps.com https://cdnjs.cloudflare.com https://fonts.gstatic.com https://fonts.googleapis.com https://static.thgcdn.cn blob: data: https://*.abtasty.com https://*.gstatic.com https://*.googleapis.com https://fonts.smct.co https://fonts.smct.io; form-action 'self' https://www.facebook.com https://www.myprotein.it https://m.myprotein.it https://checkout.myprotein.it https://connect.facebook.net https://tr.snapchat.com; img-src 'self' data: https://*.thcdn.com https://col.eum-appdynamics.com https://usage.trackjs.com https://*.lpsnmedia.net https://*.doubleclick.net https://www.google-analytics.com https://*.google.com https://cx.atdmt.com https://www.zenaps.com https: blob:; media-src 'self' https://*.thcdn.com https://*.lpsnmedia.net blob: https://static.thgcdn.cn; object-src 'self' https://*.thcdn.com https://www.youtube.com; report-uri https://csp.thehut.net/cspReport.txt; script-src 'self' 'unsafe-eval' 'unsafe-inline' data: https://*.thcdn.com https://*.thehut.net https://rum-static.pingdom.net https://*.liveperson.net https://*.lpsnmedia.net https://*.doubleclick.net https://static.cdn-apple.com https://*.liveperson.com https://geolocation.onetrust.com https://cdn.cookielaw.org https://cdn.parcellab.com https://www.googletagmanager.com https://cdnjs.cloudflare.com https://fp.zenaps.com https://www.youtube.com https://www.google-analytics.com https://*.google.com https://google.com https://connect.facebook.net https://bat.bing.com https://widget.trustpilot.com https://s.ytimg.com https://www.googletagservices.com https://*.googleapis.com https://www.facebook.com https://www.googleadservices.com https://*.gstatic.cn https://*.gstatic.com https://www.dwin1.com https://cdn.trackjs.com https://seal.digicert.com https://*.criteo.com https://static.criteo.net https://s.pinimg.com https://tpc.googlesyndication.com https://remote.captcha.com https://platform.twitter.com https://*.akamaihd.net https://*.recaptcha.net https://*.sciencebehindecommerce.com https://*.hotjar.com https://*.microsofttranslator.com https://*.trustpilot.com https://*.translate.naver.net https://*.doubleclick.net https://ln-rules.rewardstyle.com https://*.google-analytics.com https://twitter.com https://*.baidu.com https://sc-static.net https://www.google.com https://*.google.co.uk https://google.co.uk https://static.ads-twitter.com https://analytics.twitter.com https://static.thgcdn.cn https://*.contentsquare.net https://app.contentsquare.com blob: https://*.abtasty.com https://static.goqubit.com https://*.qubit.com https://sgtm.myprotein.it https://smct.co https://*.smct.co https://smct.io https://*.smct.io; style-src 'self' 'unsafe-inline' https://*.thcdn.com https://*.google.com https://*.googleapis.com https://fp.zenaps.com https://cdnjs.cloudflare.com https://www.googletagmanager.com https://*.lpsnmedia.net https://*.liveperson.net https://*.googleapis.com https://*.translate.naver.net https://*.microsofttranslator.com https://cdn.parcellab.com https://static.thgcdn.cn https://*.abtasty.com https://*.gstatic.com https://fonts.smct.co https://fonts.smct.io; upgrade-insecure-requests; report-to report-endpoint |
via: |
1.1 varnish, 1.1 varnish, 1.1 varnish |
date: |
Thu, 03 Oct 2024 02:11:52 GMT |
x-served-by: |
cache-lon420085-LON, cache-lon420130-LON, cache-ams2100104-AMS |
x-cache: |
MISS, MISS, MISS |
x-cache-hits: |
0, 0, 0 |
vary: |
accept-encoding |
strict-transport-security: |
max-age=31557600 |
alt-svc: |
h3=":443";ma=86400,h3-29=":443";ma=86400,h3-27=":443";ma=86400 |
transfer-encoding: |
chunked |
|