HTTP/1.1 301 Moved Permanently
Content-Type: text/html; charset=UTF-8
Location: https://skiguard.no/
Vary: Accept-Encoding
Server: Microsoft-IIS/10.0
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block
X-Content-Type-Options: nosniff
Content-Security-Policy: default-src 'self' googleads.g.doubleclick.net; manifest-src 'self'; script-src 'self' 'unsafe-eval' pagead2.googlesyndication.com www.google.com www.googleadservices.com storage.googleapis.com googleads.g.doubleclick.net ajax.googleapis.com *.googleapis.com www.googletagmanager.com www.google-analytics.com www.googleadservices.com *.gstatic.com googleads.g.doubleclick.net *.doubleclick.net *.youtube.com *.doubleclick.net *.aspnetcdn.com facebook.com *.facebook.com *.facebook.net 'unsafe-inline'; style-src 'self' https: 'unsafe-inline' maxcdn.bootstrapcdn.com cdnjs.cloudflare.com fonts.googleapis.com www.gstatic.com; img-src 'self' data: googleads.g.doubleclick.net i.ytimg.com gtrk.s3.amazonaws.com cdnjs.cloudflare.com www.google-analytics.com stats.g.doubleclick.net static.doubleclick.net www.gravatar.com i.simpli.fi *.gstatic.com *.googleapis.com maps.googleapis.com *.umbraco.tv umbraco.tv *.zopim.com www.facebook.com www.google.com www.google.no mt.google.com; font-src 'self' data: *.zopim.com maxcdn.bootstrapcdn.com fonts.googleapis.com fonts.gstatic.com use.typekit.net; connect-src 'self' https: www.google-analytics.com stats.g.doubleclick.net insights.hotjar.com pi-test.sagepay.com *.zopim.com wss://*.zopim.com wss://*.hotjar.com; frame-src 'self' https: vars.hotjar.com *.youtube.com *.addthis.com *.facebook.com *.youtube-nocookie.com www.youtube-nocookie.com; media-src 'self' gcs-vimeo.akamaized.net player.vimeo.com *.vimeocdn.com; object-src 'self'
Referrer-Policy: strict-origin
Feature-Policy: accelerometer 'none'; camera 'none'; geolocation 'none'; gyroscope 'none'; magnetometer 'none'; microphone 'none'; payment 'none'; usb 'none'
X-UA-Compatible: IE=Edge
Access-Control-Allow-Credentials: true
Access-Control-Request-Headers: *
Access-Control-Allow-Origin: sameorigin
Access-Control-Allow-Headers: Authorization, Origin, X-Requested-With, Content-Type, Accept, X-Token, x-custom-header, X-XSRF-TOKEN
Access-Control-Allow-Methods: GET, POST, PUT, DELETE, OPTIONS
Date: Wed, 18 May 2022 09:50:30 GMT
Content-Length: 143
HTTP/2 200
cache-control: private
content-type: text/html; charset=utf-8
vary: Accept-Encoding
x-frame-options: SAMEORIGIN
set-cookie: __RequestVerificationToken=jhbmgodnYdLV0EMIxAxbSIUlb9xAUFSVNMgYmUQLYM_9j88imNk4BswzH6OGU-h-XZRf1eZ1p14WYcEmzWi59GRsGz1K73N1cfR6rKqul0w1; path=/; HttpOnly
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
x-content-type-options: nosniff
content-security-policy: default-src 'self' googleads.g.doubleclick.net; manifest-src 'self'; script-src 'self' 'unsafe-eval' pagead2.googlesyndication.com www.google.com www.googleadservices.com storage.googleapis.com googleads.g.doubleclick.net ajax.googleapis.com *.googleapis.com www.googletagmanager.com www.google-analytics.com www.googleadservices.com *.gstatic.com googleads.g.doubleclick.net *.doubleclick.net *.youtube.com *.doubleclick.net *.aspnetcdn.com facebook.com *.facebook.com *.facebook.net 'unsafe-inline'; style-src 'self' https: 'unsafe-inline' maxcdn.bootstrapcdn.com cdnjs.cloudflare.com fonts.googleapis.com www.gstatic.com; img-src 'self' data: googleads.g.doubleclick.net i.ytimg.com gtrk.s3.amazonaws.com cdnjs.cloudflare.com www.google-analytics.com stats.g.doubleclick.net static.doubleclick.net www.gravatar.com i.simpli.fi *.gstatic.com *.googleapis.com maps.googleapis.com *.umbraco.tv umbraco.tv *.zopim.com www.facebook.com www.google.com www.google.no mt.google.com; font-src 'self' data: *.zopim.com maxcdn.bootstrapcdn.com fonts.googleapis.com fonts.gstatic.com use.typekit.net; connect-src 'self' https: www.google-analytics.com stats.g.doubleclick.net insights.hotjar.com pi-test.sagepay.com *.zopim.com wss://*.zopim.com wss://*.hotjar.com; frame-src 'self' https: vars.hotjar.com *.youtube.com *.addthis.com *.facebook.com *.youtube-nocookie.com www.youtube-nocookie.com; media-src 'self' gcs-vimeo.akamaized.net player.vimeo.com *.vimeocdn.com; object-src 'self'
referrer-policy: strict-origin
feature-policy: accelerometer 'none'; camera 'none'; geolocation 'none'; gyroscope 'none'; magnetometer 'none'; microphone 'none'; payment 'none'; usb 'none'
x-ua-compatible: IE=Edge
access-control-allow-credentials: true
access-control-request-headers: *
access-control-allow-origin: sameorigin
access-control-allow-headers: Authorization, Origin, X-Requested-With, Content-Type, Accept, X-Token, x-custom-header, X-XSRF-TOKEN
access-control-allow-methods: GET, POST, PUT, DELETE, OPTIONS
date: Wed, 18 May 2022 09:50:30 GMT
content-length: 113444
|