HTTP/1.1 301 Moved Permanently
Content-length: 0
Location: https://collegien-shop.com/
HTTP/2 302
content-type: text/html; charset=UTF-8
date: Mon, 25 Oct 2021 20:27:41 GMT
location: https://collegien-shop.fr/
server: dis-waf
x-content-type-options: nosniff
x-dis-id: 2a34d1b08c2468a18d52071d30205de31578332a
x-dis-ts: 1635193661
x-dis-waf: 1
x-xss-protection: 1; mode=block
HTTP/2 200
access-control-allow-credentials: true
access-control-allow-origin: https://collegien-shop.fr/
cache-control: no-store, no-cache, must-revalidate, proxy-revalidate
content-length: 155551
content-security-policy: default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' www.google-analytics.com secure.payzen.eu maps.googleapis.com *.paypal.com api.lyra.com api.payzen.eu ajax.googleapis.com ws.colissimo.fr api.mapbox.com www.paypalobjects.com *.google.com *.google.fr *.googleadservices.com googleads.g.doubleclick.net connect.facebook.net sw-assets.ekomiapps.de; frame-src 'self' secure.payzen.eu www.youtube.com maps.googleapis.com *.paypal.com secure.ogone.com ogone.test.v-psp.com api.lyra.com ws.colissimo.fr admin.v2019.collegien.dis-hosting.fr www.facebook.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com api.lyra.com api.payzen.eu ws.colissimo.fr api.mapbox.com widgets.ekomi.com sw-assets.ekomiapps.de; img-src 'self' data: www.google-analytics.com maps.googleapis.com *.gstatic.com placehold.it api.lyra.com *.front-commerce.com collegien-shop.fr ws.colissimo.fr api.mapbox.com *.onyourmap.com stats.g.doubleclick.net *.paypal.com *.instagram.com *.cdninstagram.com *.google.com *.google.fr googleads.g.doubleclick.net www.facebook.com scontent.cdninstagram.com scontent-cdt1-1.cdninstagram.com sw-assets.ekomiapps.de smart-widget-assets.ekomiapps.de cx.atdmt.com; font-src 'self' fonts.gstatic.com data: cdn.linearicons.com ws.colissimo.fr sw-assets.ekomiapps.de smart-widget-assets.ekomiapps.de; connect-src 'self' *.paypal.com ws.colissimo.fr widgets.ekomi.com smart-widget-assets.ekomiapps.de *.google-analytics.com stats.g.doubleclick.net; base-uri 'self'
content-type: text/html; charset=utf-8
date: Mon, 25 Oct 2021 20:27:42 GMT
etag: W/"25f9f-rxhon2tkZ7XT1a2EqTsC7pO1MM0"
expires: 0
pragma: no-cache
server: dis-waf
server-timing: config; dur=2.139112; desc="Compute config for request", loaders; dur=3.350025; desc="Initialize GraphQL loaders", app; dur=0.210112; desc="React App initialization", template; dur=39.368829; desc="Resolve initial template", getdata; dur=309.339181; desc="Resolve Apollo queries", render; dur=3.1469449999999997; desc="Render final HTML", total; dur=447.99038299999995; desc="Total Response Time"
set-cookie: connect.sid=s%3Aff00hl7ohbItgPa1YJ3FJ-RmUfGuCcPg.WsXi3jNjnNv5Cl9e6oc4fJ%2FFZfozmeVKJF9n%2BPnH7og; Path=/; Expires=Tue, 26 Oct 2021 20:27:42 GMT; HttpOnly; Secure
strict-transport-security: max-age=15552000; includeSubDomains
surrogate-control: no-store
vary: Origin, Accept-Encoding
x-content-security-policy: default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' www.google-analytics.com secure.payzen.eu maps.googleapis.com *.paypal.com api.lyra.com api.payzen.eu ajax.googleapis.com ws.colissimo.fr api.mapbox.com www.paypalobjects.com *.google.com *.google.fr *.googleadservices.com googleads.g.doubleclick.net connect.facebook.net sw-assets.ekomiapps.de; frame-src 'self' secure.payzen.eu www.youtube.com maps.googleapis.com *.paypal.com secure.ogone.com ogone.test.v-psp.com api.lyra.com ws.colissimo.fr admin.v2019.collegien.dis-hosting.fr www.facebook.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com api.lyra.com api.payzen.eu ws.colissimo.fr api.mapbox.com widgets.ekomi.com sw-assets.ekomiapps.de; img-src 'self' data: www.google-analytics.com maps.googleapis.com *.gstatic.com placehold.it api.lyra.com *.front-commerce.com collegien-shop.fr ws.colissimo.fr api.mapbox.com *.onyourmap.com stats.g.doubleclick.net *.paypal.com *.instagram.com *.cdninstagram.com *.google.com *.google.fr googleads.g.doubleclick.net www.facebook.com scontent.cdninstagram.com scontent-cdt1-1.cdninstagram.com sw-assets.ekomiapps.de smart-widget-assets.ekomiapps.de cx.atdmt.com; font-src 'self' fonts.gstatic.com data: cdn.linearicons.com ws.colissimo.fr sw-assets.ekomiapps.de smart-widget-assets.ekomiapps.de; connect-src 'self' *.paypal.com ws.colissimo.fr widgets.ekomi.com smart-widget-assets.ekomiapps.de *.google-analytics.com stats.g.doubleclick.net; base-uri 'self'
x-content-type-options: nosniff
x-content-type-options: nosniff
x-dis-id: cc664cfb1395d649620e2b03117202134c440f87
x-dis-ts: 1635193662
x-dis-waf: 1
x-dns-prefetch-control: off
x-download-options: noopen
x-frame-options: SAMEORIGIN
x-ua-compatible: IE=edge
x-webkit-csp: default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' www.google-analytics.com secure.payzen.eu maps.googleapis.com *.paypal.com api.lyra.com api.payzen.eu ajax.googleapis.com ws.colissimo.fr api.mapbox.com www.paypalobjects.com *.google.com *.google.fr *.googleadservices.com googleads.g.doubleclick.net connect.facebook.net sw-assets.ekomiapps.de; frame-src 'self' secure.payzen.eu www.youtube.com maps.googleapis.com *.paypal.com secure.ogone.com ogone.test.v-psp.com api.lyra.com ws.colissimo.fr admin.v2019.collegien.dis-hosting.fr www.facebook.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com api.lyra.com api.payzen.eu ws.colissimo.fr api.mapbox.com widgets.ekomi.com sw-assets.ekomiapps.de; img-src 'self' data: www.google-analytics.com maps.googleapis.com *.gstatic.com placehold.it api.lyra.com *.front-commerce.com collegien-shop.fr ws.colissimo.fr api.mapbox.com *.onyourmap.com stats.g.doubleclick.net *.paypal.com *.instagram.com *.cdninstagram.com *.google.com *.google.fr googleads.g.doubleclick.net www.facebook.com scontent.cdninstagram.com scontent-cdt1-1.cdninstagram.com sw-assets.ekomiapps.de smart-widget-assets.ekomiapps.de cx.atdmt.com; font-src 'self' fonts.gstatic.com data: cdn.linearicons.com ws.colissimo.fr sw-assets.ekomiapps.de smart-widget-assets.ekomiapps.de; connect-src 'self' *.paypal.com ws.colissimo.fr widgets.ekomi.com smart-widget-assets.ekomiapps.de *.google-analytics.com stats.g.doubleclick.net; base-uri 'self'
x-xss-protection: 1; mode=block
x-xss-protection: 1; mode=block
|