content-type: |
text/html; charset=UTF-8 |
content-length: |
92535 |
connection: |
close |
server: |
nginx |
date: |
Thu, 03 Oct 2024 04:57:28 GMT |
x-xss-protection: |
1; mode=block |
x-frame-options: |
SAMEORIGIN |
x-content-type-options: |
nosniff |
cache-control: |
no-cache, no-store, must-revalidate, pre-check=0, post-check=0 |
last-modified: |
Wed, 02 Oct 2024 06:41:04 GMT |
strict-transport-security: |
max-age=31536000; includeSubDomains; |
referrer-policy: |
strict-origin |
content-security-policy: |
block-all-mixed-content; default-src 'self'; base-uri 'self'; form-action 'self' flightbookings.airnewzealand.co.kr flightbookings.airnewzealand.kr flightbookings.airnewzealand.ca flightbookings.airnewzealand.cn flightbookings.airnewzealand.co.nz flightbookings.airnewzealand.co.uk flightbookings.airnewzealand.com.au flightbookings.airnewzealand.com.hk flightbookings.airnewzealand.com.sg flightbookings.airnewzealand.com.tw flightbookings.airnewzealand.com flightbookings.airnewzealand.de flightbookings.airnewzealand.eu flightbookings.airnewzealand.fr flightbookings.airnewzealand.hk flightbookings.airnewzealand.jp flightbookings.airnewzealand.pf flightbookings.airnewzealand.tw flightbookings.airnewzealand.com.cn flightbookings.grabaseat.co.nz flightbookings.airnewzealand.co.jp; script-src 'self' p-airnz.com 'unsafe-inline' 'unsafe-eval' *.googleapis.com *.gstatic.com *.google.com *.ggpht.com *.googleusercontent.com typesquare.com flightbookings.airnewzealand.co.nz player.vimeo.com www.youtube.com s.ytimg.com s.wayin.com xd.wayin.com s.engagesciences.com display.engagesciences.com *.demdex.net www.google-analytics.com analytics.google.com tagmanager.google.com www.googletagmanager.com *.doubleclick.net www.googleadservices.com www.google.com cdn-assets-prod.s3.amazonaws.com *.optimizely.com optimizely-hrd.appspot.com optimizely.s3.amazonaws.com static.hotjar.com script.hotjar.com s.swiftypecdn.com md-scp.kampyle.com sbt-prod.kampyle.com nebula-cdn.kampyle.com udc-neb.kampyle.com analytics-fe.digital-cloud-syd1.medallia.com.au https://widget.timatic.iata.org/scripts/iata-timatic-widget-live.js oc-cdn-public-oce.azureedge.net yourir.info; style-src 'unsafe-inline' p-airnz.com fonts.googleapis.com tagmanager.google.com static.hotjar.com script.hotjar.com s.swiftypecdn.com 'self' oc-cdn-public-oce.azureedge.net yourir.info; img-src https: data: static.hotjar.com script.hotjar.com; font-src p-airnz.com fonts.googleapis.com fonts.gstatic.com wf.typesquare.com dhm5hy2vn8l0l.cloudfront.net script.hotjar.com data: 'self'; media-src 'self' p-airnz.com video.cdnvue.com ; frame-src 'self' *.google.com nz.fltmaps.com player.youku.com v.qq.com player.vimeo.com www.youtube.com airnz.wufoo.com xd.wayin.com display.engagesciences.com *.demdex.net *.doubleclick.net www.googletagmanager.com *.cdn-pci.optimizely.com vars.hotjar.com nebula-cdn.kampyle.com sec.windcave.com uat.windcave.com www.airnewzealand.co.nz/payment/scripts/done.html oc-cdn-public-oce.azureedge.net blob: airnz-cargo.chooose.today airnz-corporate.chooose.today; connect-src 'self' api.airnz.io api.airnz.ai *.googleapis.com *.google.com *.gstatic.com l.typesquare.com *.demdex.net *.tt.omtrdc.net www.google-analytics.com region1.google-analytics.com region1.analytics.google.com analytics.google.com stats.g.doubleclick.net adservice.google.com *.optimizely.com https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com s.swiftypecdn.com search-api.swiftype.com md-scp.kampyle.com sbt-prod.kampyle.com nebula-cdn.kampyle.com udc-neb.kampyle.com analytics-fe.digital-cloud-syd1.medallia.com.au https://widget.timatic.iata.org/api/ sec.windcave.com uat.windcave.com unq0355446423e84eb397bc71189d78d-crm6.omnichannelengagementhub.com yourir.info; object-src 'none'; frame-ancestors 'none'; report-uri /csp-report |
permissions-policy: |
geolocation=(self "https://p-airnz.com"), camera=(), fullscreen=(self "https://www.youtube.com"), accelerometer=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), screen-wake-lock=(), sync-xhr=(*), usb=(), web-share=(), clipboard-read=(), clipboard-write=() |
vary: |
Accept-Encoding |
x-cache: |
Miss from cloudfront |
via: |
1.1 3da92f19744e3229b09a019ec66be172.cloudfront.net (CloudFront) |
x-amz-cf-pop: |
PRG50-C1 |
alt-svc: |
h3=":443"; ma=86400 |
x-amz-cf-id: |
hWjnvQu7JXH8XgMVNJDyKgmam6kapnE2gU2T9BrZ6N2tP5eFaUfS6Q== |
|