HTTP/1.1 301 Moved Permanently
Server: nginx/1.19.6
Date: Fri, 22 Oct 2021 09:42:31 GMT
Content-Type: text/html; charset=iso-8859-1
Connection: keep-alive
Location: https://www.papstar-shop.de/
Vary: Accept-Encoding
Pragma: no-cache
Expires: -1
Cache-Control: no-store, no-cache, must-revalidate, max-age=0
HTTP/2 200
server: nginx/1.19.6
date: Fri, 22 Oct 2021 09:42:32 GMT
content-type: text/html; charset=UTF-8
content-security-policy-report-only: font-src fonts.gstatic.com *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.fontawesome.com *.bootstrapcdn.com *.fact-finder.de 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.twitter.com *.facebook.com *.fact-finder.de 'self' 'unsafe-inline'; frame-ancestors *.papstar-shop.se *.papstar-shop.de 'self'; frame-src secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.youtube.com www.paypal.com www.sandbox.paypal.com *.twitter.com *.google.com *.addthis.com *.youtube.com *.facebook.com *.hotjar.com *.fact-finder.de *.pay1.de *.papstar-shop.se *.trustpilot.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com img.youtube.com maps.googleapis.com maps.gstatic.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com *.cloudflare.com *.klarna.com *.klarnacdn.net *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com 'self' data: *.fingerfood-shop.com *.usercentrics.eu *.trustedshops.com *.google.com *.papstar-shop.de *.papstar-shop.nl *.google.de *.facebook.com *.hotjar.com *.bing.com *.fact-finder.de *.magentocommerce.com 'self' 'unsafe-inline'; script-src *.adobedtm.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com js.authorize.net jstest.authorize.net www.googleadservices.com www.google-analytics.com maps.googleapis.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com *.vimeo.com www.vimeo.com www.youtube.com *.cloudflare.com *.twitter.com *.google-analytics.com googletagmanager.com *.google.com *.twimg.com *.gstatic.com *.etrusted.com *.trustedshops.com *.trustpilot.com *.usercentrics.eu *.fontawesome.com *.addthis.com s7.addthis.com m.addthis.com z.moatads.com *.addthisedge.com apis.google.com graph.facebook.com widgets.pinterest.com *.googleapis.com *.authorize.net *.cardinalcommerce.com *.ccdc02.com *.paypal.com *.ytimg.com *.signifyd.com *.googletagmanager.com *.hotjar.com *.facebook.net *.bing.com *.doubleclick.net *.fact-finder.de *.klarna.com *.pay1.de *.microsoft.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com getfirebug.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.bootstrapcdn.com *.cardinalcommerce.com *.ytimg.com *.paypal.com *.vimeocdn.com *.fingerfood-shop.com *.fact-finder.de *.hotjar.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com vimeo.com *.doubleclick.net *.google-analytics.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.cardinalcommerce.com *.vimeo.com *.usercentrics.eu *.hotjar.io *.hotjar.com *.fact-finder.de *.trustedshops.com *.sentry.io wss://*.hotjar.com 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline';
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
x-frame-options: SAMEORIGIN
vary: Accept-Encoding
content-language: de
pragma: no-cache
expires: -1
cache-control: no-store, no-cache, must-revalidate, max-age=0
accept-ranges: bytes
|