HTTP/1.1 301 Moved Permanently
Content-Type: text/html; charset=utf-8
Location: https://dreambeads-online.de
Date: Thu, 23 Dec 2021 15:47:53 GMT
HTTP/2 200
server: nginx
date: Thu, 23 Dec 2021 15:47:53 GMT
content-type: text/html; charset=UTF-8
vary: Accept-Encoding
vary: Accept-Encoding
report-to: {"group":"report-endpoint","max_age":10886400,"endpoints":[{"url":"https:\/\/ecomwise.report-uri.com\/r\/d\/csp\/reportOnly"}]}
content-security-policy-report-only: font-src *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.etrusted.com *.googleapis.com data: *.facebook.com *.helloretail.com *.googletagmanager.com *.google.com *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com *.twitter.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com 'self' 'unsafe-inline'; frame-src www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.twitter.com *.google.com *.youtube.com *.facebook.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.multisafepay.com *.hotjar.com *.doubleclick.net *.sendcloud.sc *.weltpixel.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.omtrdc.net *.trustedshops.com *.etrusted.com *.bing.com *.pinimg.com *.pinterest.com *.facebook.com *.helloretail.com *.googletagmanager.com *.google.com connect.facebook.net graph.facebook.com business.facebook.com *.multisafepay.com *.google.mk *.doubleclick.net dreambeads-online.nl data: *.klarnacdn.net *.cloudfront.net *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com www.googleadservices.com www.google-analytics.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com maps.googleapis.com *.cloudflare.com *.twitter.com *.google-analytics.com *.google.com/recaptcha/api.js *.twimg.com *.gstatic.com *.trustedshops.com *.etrusted.com *.usercentrics.eu *.fontawesome.com *.nr-data.net *.newrelic.com *.feedbackcompany.com *.bing.com *.pinimg.com *.facebook.net *.helloretail.com *.googletagmanager.com *.google.com connect.facebook.net graph.facebook.com business.facebook.com *.multisafepay.com *.hotjar.com chimpstatic.com *.doubleclick.net *.sendcloud.sc *.klarnacdn.net *.zdassets.com *.cloudfront.net *.cookiecode.nl *.googleapis.com *.addwish.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.etrusted.com *.usercentrics.eu *.fontawesome.com *.facebook.com *.helloretail.com *.googletagmanager.com *.google.com *.multisafepay.com *.bootstrapcdn.com *.cloudfront.net *.cookiecode.nl tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.sandbox.paypal.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.nr-data.net *.demdex.net *.feedbackcompany.com *.addwish.com *.pinterest.com *.trustedshops.com *.etrusted.com *.facebook.com *.helloretail.com *.googletagmanager.com *.google.com connect.facebook.net graph.facebook.com business.facebook.com *.multisafepay.com *.hotjar.com *.hotjar.io *.klarnaevt.com *.google-analytics.com *.doubleclick.net *.cookiecode.nl *.zdassets.com *.zendesk.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.klarna.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://ecomwise.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint;
strict-transport-security: max-age=31536000
content-security-policy: upgrade-insecure-requests;
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
x-frame-options: SAMEORIGIN
x-environment: Hipex/3 main
pragma: no-cache
expires: -1
cache-control: no-store, no-cache, must-revalidate, max-age=0
accept-ranges: bytes
x-environment: Hipex/3 general
|