server: |
nginx |
date: |
Sat, 25 Jan 2025 21:40:53 GMT |
content-type: |
text/html; charset=UTF-8 |
content-length: |
145343 |
connection: |
close |
vary: |
Accept-Encoding |
p3p: |
policyref="/bitrix/p3p.xml", CP="NON DSP COR CUR ADM DEV PSA PSD OUR UNR BUS UNI COM NAV INT DEM STA" |
x-powered-cms: |
Bitrix Site Manager (586eb8cf342bdbe083bbeb916f3564bd) |
set-cookie: |
PHPSESSID=0dA7OD30NAOAeGKoQk3jHiyxwuhavxKD; path=/; domain=prazdnik.vkusvill.ru; HttpOnly; SameSite=Lax,PHPSESSID=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; Max-Age=0; path=/; domain=.vkusvill.ru,PHPSESSID=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; Max-Age=0; path=/; domain=.vkusvill.ru |
expires: |
Thu, 19 Nov 1981 08:52:00 GMT |
cache-control: |
no-store |
pragma: |
no-cache |
x-frame-options: |
DENY, SAMEORIGIN, SAMEORIGIN |
content-security-policy: |
base-uri 'self'; default-src 'self' blob: data: https:; child-src 'none'; connect-src 'self' https://*.google-analytics.com wss://*.jivosite.com https://*.jivosite.com https://code.jivo.ru https://bitrix.info wss://*.bitrix.info https://mc.yandex.ru https://mc.yandex.com https://mc.yandex.md https://yandex.ru wss://mc.yandex.ru https://www.1c-bitrix.ru; font-src 'self' https://yastatic.net https://fonts.gstatic.com blob: data:; form-action 'self'; frame-ancestors 'none'; frame-src 'self' https://www.google.com https://mc.yandex.ru https://mc.yandex.com https://yandex.ru blob:; img-src 'self' https://yandex.ru https://*.yandex.ru https://mc.yandex.com https://core-renderer-tiles.maps.yandex.net https://www.googletagmanager.com https://files.jivosite.com https://code.jivo.ru blob: data:; media-src 'self' https://code.jivo.ru; manifest-src 'self'; script-src 'self' https://www.googletagmanager.com https://www.gstatic.com https://bitrix.info https://code-ya.jivosite.com https://www.google.com https://api-maps.yandex.ru https://mc.yandex.ru https://yastatic.net https://code.jivo.ru 'unsafe-inline' 'unsafe-eval' blob:; style-src 'self' https://code.jivo.ru 'unsafe-inline' 'unsafe-eval' blob: data:; report-uri /csp-report/; report-to csp-report; upgrade-insecure-requests |
x-content-security-policy: |
base-uri 'self'; default-src 'self' blob: data: https:; child-src 'none'; connect-src 'self' https://*.google-analytics.com wss://*.jivosite.com https://*.jivosite.com https://code.jivo.ru https://bitrix.info wss://*.bitrix.info https://mc.yandex.ru https://mc.yandex.com https://mc.yandex.md https://yandex.ru wss://mc.yandex.ru https://www.1c-bitrix.ru; font-src 'self' https://yastatic.net https://fonts.gstatic.com blob: data:; form-action 'self'; frame-ancestors 'none'; frame-src 'self' https://www.google.com https://mc.yandex.ru https://mc.yandex.com https://yandex.ru blob:; img-src 'self' https://yandex.ru https://*.yandex.ru https://mc.yandex.com https://core-renderer-tiles.maps.yandex.net https://www.googletagmanager.com https://files.jivosite.com https://code.jivo.ru blob: data:; media-src 'self' https://code.jivo.ru; manifest-src 'self'; script-src 'self' https://www.googletagmanager.com https://www.gstatic.com https://bitrix.info https://code-ya.jivosite.com https://www.google.com https://api-maps.yandex.ru https://mc.yandex.ru https://yastatic.net https://code.jivo.ru 'unsafe-inline' 'unsafe-eval' blob:; style-src 'self' https://code.jivo.ru 'unsafe-inline' 'unsafe-eval' blob: data:; report-uri /csp-report/; report-to csp-report; upgrade-insecure-requests |
x-webkit-csp: |
base-uri 'self'; default-src 'self' blob: data: https:; child-src 'none'; connect-src 'self' https://*.google-analytics.com wss://*.jivosite.com https://*.jivosite.com https://code.jivo.ru https://bitrix.info wss://*.bitrix.info https://mc.yandex.ru https://mc.yandex.com https://mc.yandex.md https://yandex.ru wss://mc.yandex.ru https://www.1c-bitrix.ru; font-src 'self' https://yastatic.net https://fonts.gstatic.com blob: data:; form-action 'self'; frame-ancestors 'none'; frame-src 'self' https://www.google.com https://mc.yandex.ru https://mc.yandex.com https://yandex.ru blob:; img-src 'self' https://yandex.ru https://*.yandex.ru https://mc.yandex.com https://core-renderer-tiles.maps.yandex.net https://www.googletagmanager.com https://files.jivosite.com https://code.jivo.ru blob: data:; media-src 'self' https://code.jivo.ru; manifest-src 'self'; script-src 'self' https://www.googletagmanager.com https://www.gstatic.com https://bitrix.info https://code-ya.jivosite.com https://www.google.com https://api-maps.yandex.ru https://mc.yandex.ru https://yastatic.net https://code.jivo.ru 'unsafe-inline' 'unsafe-eval' blob:; style-src 'self' https://code.jivo.ru 'unsafe-inline' 'unsafe-eval' blob: data:; report-uri /csp-report/; report-to csp-report; upgrade-insecure-requests |
x-content-type-options: |
nosniff, nosniff, nosniff |
strict-transport-security: |
max-age=16070400; includeSubDomains, max-age=31536000 |
report-to: |
{"group":"csp-report","max_age":2592000,"endpoints":[{"url":"\/csp-report\/"}]} |
x-xss-protection: |
1; mode=block |