Server | Apache |
Cache-Control | max-age=900, public |
X-Drupal-Dynamic-Cache | UNCACHEABLE |
X-UA-Compatible | IE=edge |
Content-language | fr |
X-Content-Type-Options | nosniff |
X-Frame-Options | SameOrigin |
Expires | Sun, 19 Nov 1978 05:00:00 GMT |
Last-Modified | Tue, 27 Feb 2018 00:42:51 GMT |
ETag | "1519692171-gzip" |
Vary | Cookie,Accept-Encoding |
X-Generator | Drupal 8 (https://www.drupal.org) |
Content-Security-Policy | default-src 'self' 'unsafe-inline' 'unsafe-eval' *.googleapis.com *.google-analytics.com juicebox.net *.gstatic.com *.addthis.com *.addthisedge.com *.facebook.com *.twitter.com *.flippad.com *.youtube.com *.vimeo.com *.dailymotion.com *.cloudflare.com *.addtoany.com *.ckeditor.com *.adnxs.com *.googleadservices.com *.doubleclick.net *.google.com *.google.fr *.cartes-itineraires.com *.adnxs.com *.tradedoubler.com; img-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: *.googleapis.com www.google-analytics.com juicebox.net *.gstatic.com *.addthis.com *.addthisedge.com *.facebook.com *.twitter.com *.flippad.com *.youtube.com *.vimeo.com *.dailymotion.com *.cloudflare.com *.addtoany.com *.ckeditor.com *.adnxs.com *.g.doubleclick.net *.investinreims.com *.horizon-bleu.net *.google.com *.google.fr *.tradedoubler.com; report-uri /report-csp-violation |
X-Content-Security-Policy | default-src 'self' 'unsafe-inline' 'unsafe-eval' *.googleapis.com *.google-analytics.com juicebox.net *.gstatic.com *.addthis.com *.addthisedge.com *.facebook.com *.twitter.com *.flippad.com *.youtube.com *.vimeo.com *.dailymotion.com *.cloudflare.com *.addtoany.com *.ckeditor.com *.adnxs.com *.googleadservices.com *.doubleclick.net *.google.com *.google.fr *.cartes-itineraires.com *.adnxs.com *.tradedoubler.com; img-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: *.googleapis.com www.google-analytics.com juicebox.net *.gstatic.com *.addthis.com *.addthisedge.com *.facebook.com *.twitter.com *.flippad.com *.youtube.com *.vimeo.com *.dailymotion.com *.cloudflare.com *.addtoany.com *.ckeditor.com *.adnxs.com *.g.doubleclick.net *.investinreims.com *.horizon-bleu.net *.google.com *.google.fr *.tradedoubler.com; report-uri /report-csp-violation |
X-WebKit-CSP | default-src 'self' 'unsafe-inline' 'unsafe-eval' *.googleapis.com *.google-analytics.com juicebox.net *.gstatic.com *.addthis.com *.addthisedge.com *.facebook.com *.twitter.com *.flippad.com *.youtube.com *.vimeo.com *.dailymotion.com *.cloudflare.com *.addtoany.com *.ckeditor.com *.adnxs.com *.googleadservices.com *.doubleclick.net *.google.com *.google.fr *.cartes-itineraires.com *.adnxs.com *.tradedoubler.com; img-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: *.googleapis.com www.google-analytics.com juicebox.net *.gstatic.com *.addthis.com *.addthisedge.com *.facebook.com *.twitter.com *.flippad.com *.youtube.com *.vimeo.com *.dailymotion.com *.cloudflare.com *.addtoany.com *.ckeditor.com *.adnxs.com *.g.doubleclick.net *.investinreims.com *.horizon-bleu.net *.google.com *.google.fr *.tradedoubler.com; report-uri /report-csp-violation |
X-XSS-Protection | 1; mode=block |
Content-Encoding | gzip |
Keep-Alive | timeout=5, max=100 |
Connection | Keep-Alive |
Content-Type | text/html; charset=UTF-8 |