no-cache, no-store
gzip
20950
child-src *.facebook.com connect.facebook.net ;connect-src 'self' https://*.google-analytics.com https://stats.g.doubleclick.net *.facebook.com connect.facebook.net http://*.hotjar.com:* https://*.hotjar.com:* http://*.hotjar.io https://*.hotjar.io wss://*.hotjar.com *.visualwebsiteoptimizer.com app.vwo.com *.flockler.com https://*.omappapi.com https://analytics.tiktok.com https://*.cognitoforms.com https://apps.elfsight.com https://cdn.linkedin.oribi.io ;default-src 'self' 'unsafe-inline' http://*.hotjar.com:* https://*.hotjar.com:* http://*.hotjar.io https://*.hotjar.io wss://*.hotjar.com ;font-src 'self' data: https://fonts.gstatic.com http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io ;form-action 'self' *.facebook.com connect.facebook.net secure.oxfamnovib.nl ;frame-ancestors 'self' ;frame-src 'self' https://bid.g.doubleclick.net https://atlas.oxfamnovib.nl https://11674542.fls.doubleclick.net https://www.google.com https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/ *.facebook.com connect.facebook.net https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io app.vwo.com *.visualwebsiteoptimizer.com www.youtube.com mchd-1sbqh9xf5gt4z7rdck6c-78.pub.sfmc-content.com https://cloud.supporters.oxfamnovib.nl https://twitframe.com https://platform.twitter.com https://www.anbigift.nl https://actions.oxfam.org ;img-src 'self' data: www.googletagmanager.com https://ssl.gstatic.com https://www.gstatic.com https://*.google-analytics.com https://googleads.g.doubleclick.net https://www.google.com https://www.google.nl https://11674542.fls.doubleclick.net https://ad.doubleclick.net https://ade.googlesyndication.com *.facebook.com *.facebook.net *.fbcdn.net http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io *.visualwebsiteoptimizer.com chart.googleapis.com wingify-assets.s3.amazonaws.com app.vwo.com flockler.com *.flockler.com https://*.omappapi.com https://analytics.twitter.com/ https://t.co/ https://i.ytimg.com https://px.ads.linkedin.com https://www.linkedin.com ;report-uri /cspreport ;script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://tagmanager.google.com https://*.google-analytics.com https://www.googleadservices.com https://www.google.com https://googleads.g.doubleclick.net https://www.gstatic.com/recaptcha/ https://connect.facebook.net https://graph.facebook.com https://js.facebook.com http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io 'unsafe-eval' *.visualwebsiteoptimizer.com app.vwo.com https://*.optnmnstr.com https://*.omappapi.com ;script-src-elem 'self' https://www.googletagmanager.com https://*.google-analytics.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://www.google.com https://www.gstatic.com/recaptcha/ https://connect.facebook.net https://*.hotjar.com *.visualwebsiteoptimizer.com 'unsafe-inline' *.flockler.com https://*.optnmnstr.com https://*.omappapi.com https://analytics.tiktok.com https://*.cognitoforms.com https://code.jquery.com https://platform.twitter.com https://static.ads-twitter.com https://apps.elfsight.com https://static.elfsight.com https://storage.elfsight.com https://www.youtube.com https://apis.google.com https://snap.licdn.com https://pym.nprapps.org ;style-src 'self' 'unsafe-inline' https://tagmanager.google.com https://fonts.googleapis.com *.visualwebsiteoptimizer.com app.vwo.com s3.amazonaws.com https://*.omappapi.com ;style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com *.flockler.com https://*.omappapi.com ;worker-src 'self' blob:;
text/html; charset=utf-8
Wed, 10 Jan 2024 07:38:22 GMT
-1
vibrate=(), push=(), microphone=(), camera=(), payment=()
no-cache
strict-origin-when-cross-origin
Microsoft-IIS/10.0
OxfamNovib_guid=3cee1faf-efbb-4a63-a89d-ea8a06fc896b; expires=Thu, 09-Jan-2025 07:38:23 GMT; path=/; secure; HttpOnly, .ASPXANONYMOUS=P65N7XWxZpOQTW5mzS4p6Lsw0F4Ts9mX2VFUcsWcPEbLUrq_2wrtkvvX554VX40lPHknYafrLvcYhN-gb6MtX1vlVlUwHufQQnnOj1dKtmmRgmQga-mNXXxNVObXvpnfIbjQXw2; expires=Tue, 19-Mar-2024 18:18:23 GMT; path=/; HttpOnly
max-age=31536000; includeSubdomains
Accept-Encoding
4.0.30319
NOSNIFF
SAMEORIGIN
Smartsite version 7.11.1.3 (Developer License)
master-only
1; mode=block
|