@framasoft@mobilizon.fr.head 1.8 KB

123456789101112131415161718192021222324252627
  1. HTTP/2 200
  2. server: nginx/1.18.0
  3. date: Wed, 13 Sep 2023 20:51:36 GMT
  4. content-type: application/activity+json; charset=utf-8
  5. content-length: 4505
  6. vary: Accept-Encoding
  7. access-control-allow-credentials: true
  8. access-control-allow-origin: *
  9. access-control-expose-headers:
  10. cache-control: max-age=0, private, must-revalidate
  11. content-security-policy: report-uri https://sentry.mobilizon.org/api/2/security/?sentry_key=40b6fa4d621f40efa6155d70c9618301 ; report-to csp-endpoint;upgrade-insecure-requests;frame-ancestors 'none';frame-src 'none';font-src 'self' ;media-src 'self' ;img-src 'self' data: blob: *.tile.openstreetmap.org stats.framasoft.org search.joinmobilizon.org images.unsplash.com;connect-src 'self' * blob: https://mobilizon.fr wss://mobilizon.fr stats.framasoft.org sentry.mobilizon.org;style-src 'self' ;script-src 'self' 'unsafe-eval' 'sha256-4RS22DYeB7U14dra4KcQYxmwt5HkOInieXK1NUMBmQI=' 'sha256-zJdRXhLWm9NGI6BFr+sNmHBBrjAdJdFr7MpUq0EwK58=' stats.framasoft.org;default-src 'none';base-uri 'self';manifest-src 'self';
  12. referrer-policy: strict-origin-when-cross-origin
  13. report-to: {"endpoints":[{"url":"https://sentry.mobilizon.org/api/2/security/?sentry_key=40b6fa4d621f40efa6155d70c9618301"}],"group":"csp-endpoint","max-age":10886400}
  14. reporting-endpoints: csp-endpoint="https://sentry.mobilizon.org/api/2/security/?sentry_key=40b6fa4d621f40efa6155d70c9618301"
  15. x-content-type-options: nosniff
  16. x-download-options: noopen
  17. x-frame-options: SAMEORIGIN
  18. x-permitted-cross-domain-policies: none
  19. x-request-id: F4SQjVeKHYHJc40CN9mC
  20. x-xss-protection: 0
  21. strict-transport-security: max-age=31536000; includeSubDomains; preload
  22. permissions-policy: interest-cohort=()
  23. x-clacks-overhead: GNU Terry Pratchett
  24. x-content-type-options: nosniff
  25. permissions-policy: interest-cohort=()