content-security-policy: |
style-src https://* 'unsafe-inline' 'unsafe-eval' ; frame-ancestors 'self' ; font-src https://* data: ; object-src 'self' https://cfl.dropboxstatic.com/static/ https://www.dropboxstatic.com/static/ ; connect-src https://* ws://127.0.0.1:*/ws blob: wss://dsimports.dropbox.com/ ; report-uri https://www.dropbox.com/csp_log?policy_name=metaserver-whitelist ; img-src https://* data: blob: ; default-src 'none' ; base-uri 'self' ; worker-src https://www.dropbox.com/static/serviceworker/ https://www.dropbox.com/encrypted_folder_download/service_worker.js https://www.dropbox.com/service_worker.js blob: ; form-action 'self' https://www.dropbox.com/ https://dl-web.dropbox.com/ https://photos.dropbox.com/ https://paper.dropbox.com/ https://showcase.dropbox.com/ https://www.hellofax.com/ https://app.hellofax.com/ https://www.hellosign.com/ https://app.hellosign.com/ https://docsend.com/ https://www.docsend.com/ https://help.dropbox.com/ https://navi.dropbox.jp/ https://a.sprig.com/ https://selfguidedlearning.dropboxbusiness.com/ https://instructorledlearning.dropboxbusiness.com/ https://sales.dropboxbusiness.com/ https://accounts.google.com/ https://api.login.yahoo.com/ https://login.yahoo.com/ https://experience.dropbox.com/ https://pal-test.adyen.com https://2e83413d8036243b-Dropbox-pal-live.adyenpayments.com/ https://onedrive.live.com/picker ; media-src https://* blob: ; child-src https://www.dropbox.com/static/serviceworker/ blob: ; script-src 'unsafe-eval' 'inline-speculation-rules' https://www.dropbox.com/static/api/ https://www.dropbox.com/pithos/* https://www.dropbox.com/page_success/ https://cfl.dropboxstatic.com/static/ https://www.dropboxstatic.com/static/ https://accounts.google.com/gsi/client https://canny.io/sdk.js https://www.paypal.com/sdk/js 'nonce-6YpfJsCbhlpX1Re0d4tPb4m/FTg=' ; frame-src https://* carousel: dbapi-6: dbapi-7: dbapi-8: dropbox-client: itms-apps: itms-appss:, report-uri https://www.dropbox.com/csp_log?policy_name=metaserver-dynamic ; script-src 'unsafe-eval' 'strict-dynamic' 'nonce-6YpfJsCbhlpX1Re0d4tPb4m/FTg=' 'nonce-baEFhtXRm9VsZHOUv98ZUJtGznc=' |
content-type: |
text/html; charset=utf-8 |
pragma: |
no-cache |
referrer-policy: |
strict-origin-when-cross-origin |
set-cookie: |
gvc=MjIxNTk5NjY1Mzg3MTUzMTgzMjE4OTQ5NTUxMDczODM5OTc5ODM2; Path=/; Expires=Sun, 07 Oct 2029 09:35:14 GMT; HttpOnly; Secure; SameSite=None,t=9m8W9LXg9UoXWTaVKIZY3C4q; Path=/; Domain=dropbox.com; Expires=Wed, 08 Oct 2025 09:35:14 GMT; HttpOnly; Secure; SameSite=None,__Host-js_csrf=9m8W9LXg9UoXWTaVKIZY3C4q; Path=/; Expires=Wed, 08 Oct 2025 09:35:14 GMT; Secure; SameSite=None,__Host-ss=_xOEMo8meE; Path=/; Expires=Wed, 08 Oct 2025 09:35:14 GMT; HttpOnly; Secure; SameSite=Strict,locale=ja; Path=/; Domain=dropbox.com; Expires=Sun, 07 Oct 2029 09:35:14 GMT |
x-content-type-options: |
nosniff |
x-frame-options: |
SAMEORIGIN |
x-permitted-cross-domain-policies: |
none |
x-xss-protection: |
1; mode=block |
date: |
Tue, 08 Oct 2024 09:35:14 GMT |
strict-transport-security: |
max-age=31536000; includeSubDomains |
server: |
envoy |
cache-control: |
no-cache, no-store |
vary: |
Accept-Encoding |
x-dropbox-response-origin: |
far_remote |
x-dropbox-request-id: |
0da2ca0bac6a440daea79aab408a03fc |
connection: |
close |
transfer-encoding: |
chunked |