keep-alive
Tue, 09 Jan 2024 11:38:43 GMT
max-age=31536000
Origin, Accept-Encoding, x-enable-segment
IE=Edge
bytes
h3=":443";ma=86400,h3-29=":443";ma=86400,h3-27=":443";ma=86400
private,no-store,max-age=0,no-cache,must-revalidate
gzip
default-src 'self' tpc.googlesyndication.com;frame-ancestors 'self';frame-src 'self' https://staticcdn.co.nz *.youtube.com www.facebook.com connect.facebook.net gsa://onpageload trademe.wufoo.com matterport.com *.matterport.com viewer.metamaker.istaging.com vtc.virtualtourscreator.com.au app.cloudpano.com youriguide.com virtualtour.laserfocus.co.nz s3virtualtour.esoft.com www.boxbrownie.com kuula.co tours.virtualpro.nz open.littlehinges.com ipropertyexpress.com virtual-tour.ipropertyexpress.com envisionvr.net https://api.trademe.co.nz/ https://auth.trademe.co.nz https://api.trademe.co.nz/graphql/ https://*.app.trade.me https://vimeo.com https://*.vimeo.com https://cdn.diakrit.com https://livetour.istaging.com https://vtc.virtualtourscreator.com.au https://app.cloudpano.com https://static.instavid360.com/ https://storage.googleapis.com https://www.google.com https://www.google.co.nz *.googlesyndication.com console.googletagservices.com *.doubleclick.net https://www.adsensecustomsearchads.com https://syndicatedsearch.goog *.trademepayments.co.nz:* *.pingauth.trademe.co.nz:* mfa.trademe.co.nz;font-src 'self' data: www.trademe.co.nz fonts.googleapis.com fonts.gstatic.com;img-src 'self' data: blob: www.google-analytics.com www.googletagmanager.com *.googleapis.com *.gstatic.com *.ggpht.com i.ytimg.com i.vimeocdn.com www.facebook.com https://staticcdn.co.nz *.segment.com https://api.trademe.co.nz/ *.tmcdn.co.nz https://api.trademe.co.nz/graphql/ https://trademe-prod-cdn.global.ssl.fastly.net https://*.trademe.co.nz *.google.com *.google.co.nz *.google.com.au *.google.co.uk *.google.lk *.google.co.in *.google.com.sg *.google.com.sa *.google.cn *.google.com.ph *.google.com.hk *.google.co.kr *.google.de *.google.ca *.google.co.jp *.google.com.fj *.google.co.id *.google.ae *.google.com.my *.google.co.th *.google.fr *.google.nl *.google.com.tw *.google.com.br *.google.es *.google.ie *.google.cl *.google.se *.google.ar *.google.com.vn *.googlesyndication.com *.doubleclick.net *.googleusercontent.com https://www.adsensecustomsearchads.com https://syndicatedsearch.goog api.myautoshop.co.nz images.myautoshop.co.nz sslphotos.jato.com via.placeholder.com https://static.instavid360.com/;media-src https://static.instavid360.com/;style-src 'self' 'unsafe-inline' fonts.googleapis.com www.googletagmanager.com;script-src 'self' 'sha256-6p3D5sYLHS7GnmbYG6zK0wodxUAX9p9OdfNfansieC0=' 'sha256-wZrjiTyYIWvTefnycZSRWM8/sq699i+/YTu15Rwakns=' 'report-sample' https://staticcdn.co.nz connect.facebook.net www.google-analytics.com www.googletagmanager.com *.googletagservices.com www.gstatic.com dnn506yrbagrg.cloudfront.net *.googleapis.com www.youtube.com s.ytimg.com script.crazyegg.com *.segment.com *.appboycdn.com *.google.com *.google.co.nz *.google.com.au *.google.co.uk *.google.lk *.google.co.in *.google.com.sg *.google.com.sa *.google.cn *.google.com.ph *.google.com.hk *.google.co.kr *.google.de *.google.ca *.google.co.jp *.google.com.fj *.google.co.id *.google.ae *.google.com.my *.google.co.th *.google.fr *.google.nl *.google.com.tw *.google.com.br *.google.es *.google.ie *.google.cl *.google.se *.google.ar *.google.com.vn *.googleadservices.com *.doubleclick.net *.googlesyndication.com cdn.ampproject.org https://www.adsensecustomsearchads.com https://syndicatedsearch.goog *.afterpay.com *.app.trade.me *.newrelic.com *.nr-data.net;form-action 'self' trademe.wufoo.com www.facebook.com connect.facebook.net d3f5l8ze0o4j2m.cloudfront.net https://api.trademe.co.nz/ https://api.trademe.co.nz/graphql/ https://*.app.trade.me;connect-src 'self' https://api.trademe.co.nz/ https://auth.trademe.co.nz https://api.trademe.co.nz/graphql/ *.tmcdn.co.nz https://*.app.trade.me *.segment.io *.segmentapis.com *.segment.com *.braze.com sentry.io www.facebook.com www.google-analytics.com *.gstatic.com *.googleapis.com www.googletagmanager.com *.google.com *.google.co.nz *.google.com.au *.google.co.uk *.google.lk *.google.co.in *.google.com.sg *.google.com.sa *.google.cn *.google.com.ph *.google.com.hk *.google.co.kr *.google.de *.google.ca *.google.co.jp *.google.com.fj *.google.co.id *.google.ae *.google.com.my *.google.co.th *.google.fr *.google.nl *.google.com.tw *.google.com.br *.google.es *.google.ie *.google.cl *.google.se *.google.ar *.google.com.vn google.com *.doubleclick.net *.googlesyndication.com https://www.adsensecustomsearchads.com https://syndicatedsearch.goog https://*.afterpay.com api.amplitude.com https://*.app.trade.me https://*.nr-data.net https://api.topsort.com/v2/events;child-src 'self';worker-src 'self';object-src 'none';report-uri https://www.trademe.co.nz/a/csp-report-uri
text/html; charset=utf-8
max-age=0, report-uri="https://sentry.io/api/1279183/security/?sentry_key=990566bb4d5d4445ae67eba309f51cfd&sentry_release=frend--be00d4fc"
no-cache
strict-origin-when-cross-origin
nosniff
off
noopen
0
SAMEORIGIN
none
0
|