X-DNS-Prefetch-Control | off |
X-Frame-Options | SAMEORIGIN |
Strict-Transport-Security | max-age=15768000; includeSubDomains |
X-Download-Options | noopen |
X-Content-Type-Options | nosniff |
X-XSS-Protection | 1; mode=block |
Content-Security-Policy | script-src 'self' 'unsafe-inline' 'unsafe-eval' *.google.com *.maxcdn.com *.linkedin.com *.googlesyndication.com *.google.com *.cloudflare.com *.bootstrapcdn.com *.googletagservices.com *.jsdelivr.net *.google-analytics.com *.twitter.com *.facebook.com *.facebook.net *.googleadservices.com *.gstatic.com *.doubleclick.net *.youtube.com *.youtu.be *.dailymotion.com *.vine.co *.youku.com *.instagram.com *.vimeo.com *.ampproject.org *.ampproject.net *.googleapis.com *.infolinks.com *.pubmatic.com *.quantserve.com; frame-src 'self' *.google.com *.maxcdn.com *.linkedin.com *.googlesyndication.com *.google.com *.cloudflare.com *.bootstrapcdn.com *.googletagservices.com *.jsdelivr.net *.google-analytics.com *.twitter.com *.facebook.com *.facebook.net *.googleadservices.com *.gstatic.com *.doubleclick.net *.youtube.com *.youtu.be *.dailymotion.com *.vine.co *.youku.com *.instagram.com *.vimeo.com *.ampproject.org *.ampproject.net *.googleapis.com *.infolinks.com *.pubmatic.com *.quantserve.com; object-src 'self' *.google.com *.maxcdn.com *.linkedin.com *.googlesyndication.com *.google.com *.cloudflare.com *.bootstrapcdn.com *.googletagservices.com *.jsdelivr.net *.google-analytics.com *.twitter.com *.facebook.com *.facebook.net *.googleadservices.com *.gstatic.com *.doubleclick.net *.youtube.com *.youtu.be *.dailymotion.com *.vine.co *.youku.com *.instagram.com *.vimeo.com *.ampproject.org *.ampproject.net *.googleapis.com *.infolinks.com *.pubmatic.com *.quantserve.com; img-src * data: blob: filesystem:; style-src 'self' 'unsafe-inline'; report-uri /report-violation |
X-Content-Security-Policy | script-src 'self' 'unsafe-inline' 'unsafe-eval' *.google.com *.maxcdn.com *.linkedin.com *.googlesyndication.com *.google.com *.cloudflare.com *.bootstrapcdn.com *.googletagservices.com *.jsdelivr.net *.google-analytics.com *.twitter.com *.facebook.com *.facebook.net *.googleadservices.com *.gstatic.com *.doubleclick.net *.youtube.com *.youtu.be *.dailymotion.com *.vine.co *.youku.com *.instagram.com *.vimeo.com *.ampproject.org *.ampproject.net *.googleapis.com *.infolinks.com *.pubmatic.com *.quantserve.com; frame-src 'self' *.google.com *.maxcdn.com *.linkedin.com *.googlesyndication.com *.google.com *.cloudflare.com *.bootstrapcdn.com *.googletagservices.com *.jsdelivr.net *.google-analytics.com *.twitter.com *.facebook.com *.facebook.net *.googleadservices.com *.gstatic.com *.doubleclick.net *.youtube.com *.youtu.be *.dailymotion.com *.vine.co *.youku.com *.instagram.com *.vimeo.com *.ampproject.org *.ampproject.net *.googleapis.com *.infolinks.com *.pubmatic.com *.quantserve.com; object-src 'self' *.google.com *.maxcdn.com *.linkedin.com *.googlesyndication.com *.google.com *.cloudflare.com *.bootstrapcdn.com *.googletagservices.com *.jsdelivr.net *.google-analytics.com *.twitter.com *.facebook.com *.facebook.net *.googleadservices.com *.gstatic.com *.doubleclick.net *.youtube.com *.youtu.be *.dailymotion.com *.vine.co *.youku.com *.instagram.com *.vimeo.com *.ampproject.org *.ampproject.net *.googleapis.com *.infolinks.com *.pubmatic.com *.quantserve.com; img-src * data: blob: filesystem:; style-src 'self' 'unsafe-inline'; report-uri /report-violation |
X-WebKit-CSP | script-src 'self' 'unsafe-inline' 'unsafe-eval' *.google.com *.maxcdn.com *.linkedin.com *.googlesyndication.com *.google.com *.cloudflare.com *.bootstrapcdn.com *.googletagservices.com *.jsdelivr.net *.google-analytics.com *.twitter.com *.facebook.com *.facebook.net *.googleadservices.com *.gstatic.com *.doubleclick.net *.youtube.com *.youtu.be *.dailymotion.com *.vine.co *.youku.com *.instagram.com *.vimeo.com *.ampproject.org *.ampproject.net *.googleapis.com *.infolinks.com *.pubmatic.com *.quantserve.com; frame-src 'self' *.google.com *.maxcdn.com *.linkedin.com *.googlesyndication.com *.google.com *.cloudflare.com *.bootstrapcdn.com *.googletagservices.com *.jsdelivr.net *.google-analytics.com *.twitter.com *.facebook.com *.facebook.net *.googleadservices.com *.gstatic.com *.doubleclick.net *.youtube.com *.youtu.be *.dailymotion.com *.vine.co *.youku.com *.instagram.com *.vimeo.com *.ampproject.org *.ampproject.net *.googleapis.com *.infolinks.com *.pubmatic.com *.quantserve.com; object-src 'self' *.google.com *.maxcdn.com *.linkedin.com *.googlesyndication.com *.google.com *.cloudflare.com *.bootstrapcdn.com *.googletagservices.com *.jsdelivr.net *.google-analytics.com *.twitter.com *.facebook.com *.facebook.net *.googleadservices.com *.gstatic.com *.doubleclick.net *.youtube.com *.youtu.be *.dailymotion.com *.vine.co *.youku.com *.instagram.com *.vimeo.com *.ampproject.org *.ampproject.net *.googleapis.com *.infolinks.com *.pubmatic.com *.quantserve.com; img-src * data: blob: filesystem:; style-src 'self' 'unsafe-inline'; report-uri /report-violation |
Content-Type | text/html; charset=utf-8 |
ETag | W/"1400-W96MOjUk0OMagsZeqJj0bg" |
set-cookie | connect.sid=s%3AQ7k7kYPwFBBy5xuDACzuWBv3IU9ojJgw.mWA%2BqCf6%2FtWdy3XAiPpHvwG2FB%2B0ll2fe0boJDMl06w; Domain=.skop.io; Path=/; Expires=Wed, 04 Apr 2018 08:41:51 GMT; HttpOnly; Secure |
Vary | Accept-Encoding |
Content-Encoding | gzip |
Connection | keep-alive |
Transfer-Encoding | chunked |