content-type: |
text/html |
content-length: |
257026 |
connection: |
close |
x-amz-id-2: |
i5i8l2HBmyliiqLGDk/TyiHx5eI1aglzDszLrvrWIWJ4vH6ooJyqdjY7W0/3zPYwgcFL8JgOXiA= |
x-amz-request-id: |
RD4SADHSPRQ1KNE7 |
date: |
Wed, 02 Oct 2024 21:27:33 GMT |
cache-control: |
public, max-age=0, must-revalidate |
last-modified: |
Fri, 02 Dec 2022 13:37:47 GMT |
etag: |
"d8d07853c3e4c867af4d0cb14e951edd" |
server: |
AmazonS3 |
vary: |
Accept-Encoding |
content-security-policy: |
default-src 'self' *.disquscdn.com *.disqus.com disqus.com *.safeframe.googlesyndication.com *.google.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' 'unsafe-eval' embed.smartframe.net embed-cdn.gettyimages.com static.smartframe.net *.disquscdn.com *.disqus.com rec.smartlook.com *.trustpilot.com www.google-analytics.com cdn.jsdelivr.net cdnjs.cloudflare.com www.dwin1.com *.adnxs.com *.2mdn.net *.dwin1.com cdn.ampproject.org *.googlesyndication.com *.googletagservices.com *.google.it *.privacymanager.io *.pubwise.io *.g.doubleclick.net *.doubleclick.net *.facebook.net connect.facebook.net *.ibytedtos.com *.upviral.com *.googleoptimize.com tagmanager.google.com *.google.com *.ipstatp.com analytics.tiktok.com *.tiktok.com www.googletagmanager.com www.googleadservices.com googleads.g.doubleclick.net www.gstatic.com connect.facebook.net apis.google.com static.hotjar.com script.hotjar.com cdn.onesignal.com maps.googleapis.com www.google-analytics.com www.google.com js.stripe.com onesignal.com *.freshchat.com *.iubenda.com; style-src 'self' 'unsafe-inline' *.disquscdn.com *.disqus.com optimize.google.com tagmanager.google.com cdn.jsdelivr.net cdnjs.cloudflare.com *.google.com fonts.googleapis.com *.freshchat.com *.iubenda.com; img-src 'self' data: cdn.viglink.com *.disquscdn.com *.disqus.com www.google-analytics.com images.ctfassets.net *.googletagmanager.com *.hotjar.com *.adnxs.com *.adform.net *.g.doubleclick.net *.googlesyndication.com pagead2.googlesyndication.com upviral.s3.amazonaws.com tagmanager.google.com *.google.com *.gstatic.com tp-images-compressed.s3-eu-west-1.amazonaws.com go.nordvpn.net get.surfshark.net media.go2speed.org *.yceml.net *.emjcd.com *.dotomi.com *.tradedoubler.com vht.tradedoubler.com www.fr135.net www.lduhtrp.net www.tqlkg.com impit.tradedoubler.com mproxy.banner.linksynergy.com static-dscn.net www.lduhtrp.net impit.tradedoubler.com mail.dt51.net www.tqlkg.com ad.linksynergy.com disneyplus.bn5x.net imp.pxf.io a.impactradius-go.com www.google.com www.google.it www.google.en www.google.es googleads.g.doubleclick.net csi.gstatic.com mediamob.g2afse.com cors-anywhere.herokuapp.com graph.facebook.com *.googleusercontent.com platform-lookaside.fbsbx.com tp-images-compressed.s3.amazonaws.com cx.atdmt.com images.s3.amazonaws.com images.unsplash.com images.pexels.com covers.s3-eu-west-1.amazonaws.com d1ug1wtffjdh7z.cloudfront.net www.google-analytics.com www.facebook.com stats.g.doubleclick.net tp-network-images.s3.amazonaws.com tp-network-covers.s3-eu-west-1.amazonaws.com *.iubenda.com; child-src 'self' embed.smartframe.net *.disquscdn.com www.facebook.com disqus.com *.disqus.com www.youtube.com images.ctfassets.net *.2mdn.net optimize.google.com *.doubleclick.net *.trustpilot.com *.googletagservices.com *.privacymanager.io *.googlesyndication.com acdn.adnxs.com *.g.doubleclick.net g.doubleclick.net *.google.com https://optimize.google.com mail: fb-messenger: messenger: whatsapp: blob: data: *.upviral.com 'unsafe-inline' 'unsafe-eval' *.googleapis.com vars.hotjar.com accounts.google.com staticxx.facebook.com js.stripe.com www.google.com onesignal.com *.freshchat.com *.iubenda.com; font-src 'self' data: *.disquscdn.com *.disqus.com fonts.gstatic.com cdnjs.cloudflare.com http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io *.iubenda.com; connect-src 'self' data: d54hsn8ou0.execute-api.eu-central-1.amazonaws.com static.smartframe.net *.googletagmanager.com *.disquscdn.com *.disqus.com ipinfo.io *.facebook.net connect.facebook.net mediamob.g2afse.com *.google.com *.gstatic.com api.rlcdn.com api.pubwise.io id5-sync.com *.adnxs.com *.launch.liveramp.com *.privacymanager.io *.googlesyndication.com *.facebook.com *.doubleclick.net *.upviral.com dashboard.togetherprice.com:13001 tp-app-config.s3.eu-west-1.amazonaws.com *.togetherprice.com api.amplitude.com cors-anywhere.herokuapp.com d1ug1wtffjdh7z.cloudfront.net togetherprice.freshdesk.com graph.facebook.com people.googleapis.com in.hotjar.com www.google-analytics.com api.togetherprice.com apiv2.togetherprice.com wss://apiv2.staging.togetherprice.com wss://apiv2.togetherprice.com vc.hotjar.io *.hotjar.com wss://*.hotjar.com fonts.googleapis.com onesignal.com *.algolianet.com *.iubenda.com; manifest-src 'self'; worker-src 'self' blob:; frame-ancestors 'self' optimize.google.com |
expect-ct: |
max-age=1, enforce, report-uri=\"https://www.togetherprice.com/report\" |
strict-transport-security: |
max-age=63072000; includeSubDomains; preload |
x-frame-options: |
DENY |
x-xss-protection: |
1; mode=block |
x-content-type-options: |
nosniff |
x-cache: |
Hit from cloudfront |
via: |
1.1 5869d8337913ed7453262c3cf9c9a9e6.cloudfront.net (CloudFront) |
x-amz-cf-pop: |
AMS58-P4 |
x-amz-cf-id: |
-hBqt8w9_Sg9JdQM1a4iYRdaWhBIsJOEe5kW2XBNuus5gk57b2OcIg== |