HTTP/1.1 302 Found
Server: nginx
Date: Thu, 28 Oct 2021 20:44:48 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
X-Powered-By: PHP/7.3.16
Pragma: no-cache
Cache-Control: max-age=0, must-revalidate, no-cache, no-store
Expires: Wed, 28 Oct 2020 20:44:48 GMT
Content-Security-Policy-Report-Only: font-src cdn.nznature.co.nz fonts.gstatic.com 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src www.paypal.com www.sandbox.paypal.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com www.google.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com cdn.nznature.co.nz www.facebook.com www.google.com www.google.co.nz google-analytics.com privymktg.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com www.googleadservices.com www.google-analytics.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com cdn.nznature.co.nz connect.facebook.net www.gstatic.com www.google.com widget.privy.com downloads.mailchimp.com chimpstatic.com mc.us16.list-manage.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.nznature.co.nz fonts.googleapis.com assets.privy.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src js.stripe.com m.stripe.com x.klarnacdn.net klarna.com cdn.nznature.co.nz stats.g.doubleclick.net www.google-analytics.com api.privy.com www.facebook.com 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline';
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
Set-Cookie: PHPSESSID=f168ecca32af5a5bf9c14d87313368c2; expires=Thu, 28-Oct-2021 21:44:48 GMT; Max-Age=3600; path=/; domain=nznature.com; HttpOnly
Location: https://www.nznature.com/
Access-Control-Allow-Headers: x-requested-with
X-UA-Compatible: IE=edge
HTTP/2 200
server: nginx
date: Thu, 28 Oct 2021 20:44:49 GMT
content-type: text/html; charset=UTF-8
content-length: 228398
x-powered-by: PHP/7.3.16
pragma: no-cache
cache-control: max-age=0, must-revalidate, no-cache, no-store
expires: Wed, 28 Oct 2020 20:44:49 GMT
content-security-policy-report-only: font-src cdn.nznature.co.nz fonts.gstatic.com 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src www.paypal.com www.sandbox.paypal.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com www.google.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com cdn.nznature.co.nz www.facebook.com www.google.com www.google.co.nz google-analytics.com privymktg.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com www.googleadservices.com www.google-analytics.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com cdn.nznature.co.nz connect.facebook.net www.gstatic.com www.google.com widget.privy.com downloads.mailchimp.com chimpstatic.com mc.us16.list-manage.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.nznature.co.nz fonts.googleapis.com assets.privy.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src js.stripe.com m.stripe.com x.klarnacdn.net klarna.com cdn.nznature.co.nz stats.g.doubleclick.net www.google-analytics.com api.privy.com www.facebook.com 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline';
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
x-frame-options: SAMEORIGIN
set-cookie: X-Magento-Vary=fb939bdda356c7711cb90397c3cc089539ba3672; expires=Thu, 28-Oct-2021 21:44:49 GMT; Max-Age=3600; path=/; secure; HttpOnly
access-control-allow-headers: x-requested-with
x-ua-compatible: IE=edge
|