HTTP/1.1 302 Found
Server: nginx
Date: Mon, 01 Nov 2021 22:46:27 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Set-Cookie: PHPSESSID=fogsi2gfv73148fr8ucff89s11; expires=Mon, 01-Nov-2021 23:46:27 GMT; Max-Age=3600; path=/; domain=airpress.de; HttpOnly; SameSite=Lax
Set-Cookie: X-Magento-Vary=c58cc7336841735bf5ef13185766282824a9d073; expires=Mon, 01-Nov-2021 23:46:27 GMT; Max-Age=3600; path=/; HttpOnly; SameSite=Lax
Location: https://airpress.de/
Content-Security-Policy-Report-Only: font-src *.gstatic.com *.hotjar.com *.orbitvu.co *.adyen.com *.app-us1.com 'self' data: *.doubleclick.net *.facebook.com 'self' 'unsafe-inline'; form-action *.facebook.com *.adyen.com *.app-us1.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src www.paypal.com www.sandbox.paypal.com player.vimeo.com *.adyen.com *.hotjar.com *.belco.io *.youtube.com *.facebook.com *.app-us1.com *.google.com *.doubleclick.net 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com *.adyen.com *.facebook.com www.google-analytics.com www.google.com www.googletagmanager.com www.google.nl *.doubleclick.net *.orbitvu.co orbitvu.co blob: data: amazonaws.com *.app-us1.com *.hubspot.com 'self' data: *.google.com *.google.bg *.facebook.net 'self' 'unsafe-inline'; script-src www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com *.adyen.com www.google-analytics.com *.facebook.com *.facebook.net *.hotjar.com *.belco.io *.createsend1.com *.orbitvu.co orbitvu.co www.google.com *.gstatic.com *.googleadservices.com *.doubleclick.net *.app-us1.com *.hs-scripts.com *.hscollectedforms.com *.hscollectedforms.net *.hs-banner.com *.hs-analytics.com *.hs-analytics.net *.google.com *.googletagmanager.com jquery.sellxed.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.googleapis.com *.orbitvu.co *.adyen.com *.app-us1.com *.doubleclick.net *.facebook.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.belco.io *.adyen.com *.app-us1.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.belco.io wss://*.belco.io *.orbitvu.cloud *.adyen.com *.app-us1.com www.google-analytics.com *.doubleclick.net *.google.com *.hotjar.com *.google-analytics.com *.facebook.com *.facebook.net 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline';
Content-Security-Policy: upgrade-insecure-requests;
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
Vary: Accept-Encoding
Pragma: no-cache
Expires: -1
Cache-Control: no-store, no-cache, must-revalidate, max-age=0
Strict-Transport-Security: max-age=31536000; includeSubDomains
HTTP/2 200
server: nginx
date: Mon, 01 Nov 2021 22:46:27 GMT
content-type: text/html; charset=UTF-8
content-security-policy-report-only: font-src *.gstatic.com *.hotjar.com *.orbitvu.co *.adyen.com *.app-us1.com 'self' data: *.doubleclick.net *.facebook.com 'self' 'unsafe-inline'; form-action *.facebook.com *.adyen.com *.app-us1.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src www.paypal.com www.sandbox.paypal.com player.vimeo.com *.adyen.com *.hotjar.com *.belco.io *.youtube.com *.facebook.com *.app-us1.com *.google.com *.doubleclick.net 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com *.adyen.com *.facebook.com www.google-analytics.com www.google.com www.googletagmanager.com www.google.nl *.doubleclick.net *.orbitvu.co orbitvu.co blob: data: amazonaws.com *.app-us1.com *.hubspot.com 'self' data: *.google.com *.google.bg *.facebook.net 'self' 'unsafe-inline'; script-src www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com *.adyen.com www.google-analytics.com *.facebook.com *.facebook.net *.hotjar.com *.belco.io *.createsend1.com *.orbitvu.co orbitvu.co www.google.com *.gstatic.com *.googleadservices.com *.doubleclick.net *.app-us1.com *.hs-scripts.com *.hscollectedforms.com *.hscollectedforms.net *.hs-banner.com *.hs-analytics.com *.hs-analytics.net *.google.com *.googletagmanager.com jquery.sellxed.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.googleapis.com *.orbitvu.co *.adyen.com *.app-us1.com *.doubleclick.net *.facebook.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.belco.io *.adyen.com *.app-us1.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.belco.io wss://*.belco.io *.orbitvu.cloud *.adyen.com *.app-us1.com www.google-analytics.com *.doubleclick.net *.google.com *.hotjar.com *.google-analytics.com *.facebook.com *.facebook.net 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline';
content-security-policy: upgrade-insecure-requests;
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
x-frame-options: SAMEORIGIN
vary: Accept-Encoding
pragma: no-cache
expires: -1
cache-control: no-store, no-cache, must-revalidate, max-age=0
accept-ranges: bytes
strict-transport-security: max-age=31536000; includeSubDomains
|