keep-alive
gzip
default-src 'none'; manifest-src 'self'; connect-src 'self' https://www.google-analytics.com/ https://*.google-analytics.com/ https://stats.g.doubleclick.net/ https://analytics.google.com/ https://*.analytics.google.com/ https://www.googletagmanager.com/; script-src 'report-sample' 'self' https://www.googletagmanager.com/ https://www.google-analytics.com/; script-src-attr 'none'; font-src 'self'; img-src 'self' https://static.jeurissen.co/ https://www.googletagmanager.com/ https://www.google-analytics.com/; style-src 'self'; base-uri 'none'; form-action 'none'; frame-ancestors 'none'; sandbox allow-same-origin allow-scripts allow-popups-to-escape-sandbox; block-all-mixed-content; upgrade-insecure-requests; worker-src 'report-sample' 'self' https://www.googletagmanager.com/ https://www.google-analytics.com/; frame-src 'none'; object-src 'none'; style-src-attr 'self'; script-src-elem 'report-sample' 'self' https://www.googletagmanager.com/ https://www.google-analytics.com/; style-src-elem 'self'; report-uri https://api.jeurissen.co/reports/csp/carlos.jeurissen.co; report-to csp-endpoint
text/html; charset=utf-8
unsafe-none; report-to=coep-endpoint
same-origin; report-to=coop-endpoint
Wed, 10 Jan 2024 14:46:08 GMT
unsized-media,unoptimized-images,accelerometer,ambient-light-sensor,document-write,speaker,autoplay,camera,encrypted-media,fullscreen,geolocation,gyroscope,magnetometer,microphone,midi,payment,picture-in-picture,sync-xhr,usb,battery,display-capture,document-domain,layout-animations,legacy-image-formats,oversized-images,publickey-credentials-get,vibrate,vr,wake-lock,web-share,xr-spatial-tracking,xr,screen-wake-lock, *;report-to=doc-endpoint
W/"63d26d50-224d"
interest-cohort 'none'; accelerometer 'none'; autoplay 'none'; camera 'none'; encrypted-media 'none'; fullscreen 'none'; geolocation 'none'; gyroscope 'none'; magnetometer 'none'; microphone 'none'; midi 'none'; payment 'none'; picture-in-picture 'none'; sync-xhr 'none'; usb 'none'; ambient-light-sensor 'none'
Thu, 26 Jan 2023 12:08:48 GMT
{"report_to":"nel-endpoint","max_age":0,"include_subdomains":true}
interest-cohort=(), accelerometer=(), autoplay=(), camera=(), encrypted-media=(), fullscreen=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), sync-xhr=(), usb=(), ambient-light-sensor=()
strict-origin-when-cross-origin
{"group":"csp-endpoint","max_age":0,"include_subdomains":true,"endpoints":[{"url":"https://api.jeurissen.co/reports/csp/carlos.jeurissen.co"}]}, {"group":"coop-endpoint","max_age":0,"include_subdomains":true,"endpoints":[{"url":"https://api.jeurissen.co/reports/coop/carlos.jeurissen.co"}]}, {"group":"doc-endpoint","max_age":0,"include_subdomains":true,"endpoints":[{"url":"https://api.jeurissen.co/reports/doc/carlos.jeurissen.co"}]}, {"group":"coep-endpoint","max_age":0,"include_subdomains":true,"endpoints":[{"url":"https://api.jeurissen.co/reports/coep/carlos.jeurissen.co"}]}, {"group":"nel-endpoint","max_age":0,"include_subdomains":true,"endpoints":[{"url":"https://api.jeurissen.co/reports/nel/carlos.jeurissen.co"}]}, {"max_age":0,"include_subdomains":true,"endpoints":[{"url":"https://api.jeurissen.co/reports/general/carlos.jeurissen.co"}]}
nginx
max-age=31536000; includeSubDomains; preload
Accept-Encoding
nosniff
off
noopen
DENY
none
IE=edge
1; mode=block; report=https://api.jeurissen.co/reports/xss/web/carlos.jeurissen.co
|