Server | nginx |
Content-Type | text/html; charset=UTF-8 |
Transfer-Encoding | chunked |
Connection | keep-alive |
X-Content-Type-Options | nosniff |
Vary | Accept-Encoding, Accept-Encoding,Cookie |
Expires | Thu, 01 Jan 1970 00:00:00 GMT |
Cache-Control | private, must-revalidate, max-age=0 |
Last-Modified | Mon, 05 Feb 2018 09:53:06 GMT |
Content-Language | en-GB |
Strict-Transport-Security | max-age=31536000 |
Content-Security-Policy | default-src 'self'; connect-src *.hud.ac.uk 'self' embedr.flickr.com links.services.disqus.com geo.query.yahoo.com; script-src disqus.com *.hud.ac.uk maxcdn.bootstrapcdn.com cdnjs.cloudflare.com cse.google.com www.google.com *.gravatar.com 'self' 'unsafe-inline' 'unsafe-eval' *.wp.com *.analytics.yahoo.com code.jquery.com *.google-analytics.com *.flickr.com *.googleapis.com *.gstatic.com *.disqus.com *.disquscdn.com; img-src * data:; style-src 'self' 'unsafe-inline' maxcdn.bootstrapcdn.com *.hud.ac.uk *.gravatar.com *.wp.com *.disquscdn.com *.googleapis.com; font-src 'self' data: *.hud.ac.uk maxcdn.bootstrapcdn.com *.wp.com fonts.gstatic.com themes.googleusercontent.com; frame-src 'self' files.huddersfield.exposed *.youtube.com *.flickr.com *.disqus.com disqus.com *.google.co.uk *.google.com *.wp.com *.wordpress.com *.archive.org archive.org; object-src 'self'; media-src 'self' files.huddersfield.exposed |
X-XSS-Protection | 0 |
Content-Encoding | gzip |