HTTP/1.1 301 Moved Permanently
Date: Sun, 12 Dec 2021 08:25:54 GMT
Connection: keep-alive
Cache-Control: max-age=3600
Expires: Sun, 12 Dec 2021 09:25:54 GMT
Location: https://migrosonline.ch/
X-Content-Type-Options: nosniff
Server: cloudflare
CF-RAY: 6bc590917f5a191e-EWR
HTTP/2 301
date: Sun, 12 Dec 2021 08:25:54 GMT
location: https://shop.migros.ch/
cache-control: max-age=3600
expires: Sun, 12 Dec 2021 09:25:54 GMT
expect-ct: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
strict-transport-security: max-age=31536000; includeSubDomains; preload
x-content-type-options: nosniff
server: cloudflare
cf-ray: 6bc59091bac617f1-EWR
HTTP/2 200
date: Sun, 12 Dec 2021 08:25:55 GMT
content-type: text/html
last-modified: Fri, 10 Dec 2021 14:01:08 GMT
pragma: no-cache
cache-control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
content-security-policy: default-src 'self'; img-src 'self' data: *.migros.ch *.googleapis.com www.googleadservices.com *.googleusercontent.com *.googletagmanager.com *.gstatic.com tagmanager.google.com cct.connects.ch profity.ch *.profity.ch *.xcampaign.ch partners.webmasterplan.com tbs.tradedoubler.com image.migros.ch migros.rokka.io migros-test.rokka.io migros-coupons-test.rokka.io migros-filialen-test.rokka.io migros-filialen.rokka.io *.atdmt.com *.google.ch maps.gstatic.com *.facebook.com *.google.com *.g.doubleclick.net 6841363.fls.doubleclick.net *.google-analytics.com www-leshop-ch-cld-res.cloudinary.com bat.bing.com *.ctfassets.net siteintercept.qualtrics.com *.hotjar.io *.hotjar.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.migros.ch www.googleadservices.com tc.connects.ch *.google-analytics.com maps.googleapis.com *.googletagmanager.com tagmanager.google.com www.google.com www.google.ch *.getback.ch *.googleoptimize.com optimize.google.com connect.facebook.net googleads.g.doubleclick.net bat.bing.com static.profity.ch siteintercept.qualtrics.com *.siteintercept.qualtrics.com *.hotjar.io *.hotjar.com; style-src 'self' 'unsafe-inline' *.migros.ch tagmanager.google.com fonts.googleapis.com cdn.fonts.net; font-src 'self' *.migros.ch fonts.googleapis.com fonts.gstatic.com cdn.fonts.net *.hotjar.io *.hotjar.com; connect-src 'self' *.migros.ch www-leshop-ch-cld-res.cloudinary.com www.facebook.com stats.g.doubleclick.net *.lacmp.net *.leshop.ch *.leshop-test.ch analytics.google.com *.google-analytics.com *.ingest.sentry.io *.contentful.com firebaseinstallations.googleapis.com firebaseremoteconfig.googleapis.com siteintercept.qualtrics.com *.siteintercept.qualtrics.com *.hotjar.io *.hotjar.com mo-da-serverside-tracking-sbx.ey.r.appspot.com mo-da-adrecommender-int.oa.r.appspot.com; child-src 'self' *.migros.ch optimize.google.com *.youtube.com *.facebook.com pay.sandbox.datatrans.com pay.datatrans.com 9229177.fls.doubleclick.net 9272754.fls.doubleclick.net 6841363.fls.doubleclick.net *.lacmp.net leshop.queue-it.net siteintercept.qualtrics.com *.siteintercept.qualtrics.com migroscx.qualtrics.com *.hotjar.io *.hotjar.com; object-src 'none';
x-xss-protection: 1; mode=block
x-content-type-options: nosniff
strict-transport-security: max-age=31536000; includeSubDomains; preload
referrer-policy: strict-origin-when-cross-origin
x-frame-options: SAMEORIGIN
accept-ranges: bytes
set-cookie: c546c5bcfc0b1f483399482587140d2a=d5b82aca1b754b4cb4b233585ab62f6d; path=/; HttpOnly; Secure
cf-cache-status: DYNAMIC
expect-ct: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
server: cloudflare
cf-ray: 6bc590937ab21a40-EWR
|