HTTP/1.1 200 OKConnection: keep-aliveContent-Length: 250560Content-Security-Policy-Report-Only: prefetch-src static.klaviyo.com; font-src *.bobux.com *.typekit.net data: strutagiocdn.blob.core.windows.net maxcdn.bootstrapcdn.com js.klevu.com static.klaviyo.com fonts.googleapis.com fonts.gstatic.com 'self' 'unsafe-inline'; form-action *.bobux.com www.facebook.com www.youtube.com static.klaviyo.com 'self' 'unsafe-inline'; frame-ancestors *.typeform.com 'self' 'unsafe-inline'; frame-src www.paypal.com www.sandbox.paypal.com *.bobux.com *.strut.fit *.laybuy.com *.typeform.com www.facebook.com www.youtube.com strutfit.azurewebsites.net *.klevu.com static.klaviyo.com player.vimeo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com *.bobux.com www.facebook.com data: strutagiocdn.blob.core.windows.net static.afterpay.com static.secure-afterpay.com.au a.klaviyo.com static.klaviyo.com js.klevu.com *.cloudfront.net www.google.com www.google.com.ua bat.bing.com portal.sandbox.afterpay.com connect.facebook.net maps.gstatic.com www.youtube.com scontent.cdninstagram.com cx.atdmt.com maps.googleapis.com integration-assets.laybuy.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com js.authorize.net jstest.authorize.net www.googleadservices.com www.google-analytics.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com js.braintreegateway.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com *.bobux.com foursixty.com connect.facebook.net *.newrelic.com *.nr-data.net static.klaviyo.com *.klaviyo.com *.typeform.com solve.io strutagiocdn.blob.core.windows.net js.klevu.com static.prod-00.bobux.solvestack.net *.solvestack.net maps.googleapis.com www.gstatic.com www.google.com portal-sandbox.afterpay.com fullstory.com *.fullstory.com bat.bing.com portal.afterpay.com portal.sandbox.afterpay.com www.googletagmanager.com *.ksearchnet.com fonts.googleapis.com data: 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.bobux.com *.klaviyo.com static.klaviyo.com foursixty.com *.typekit.net maxcdn.bootstrapcdn.com js.klevu.com fonts.googleapis.com fonts.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.klaviyo.com *.strut.fit *.laybuy.com static.klaviyo.com *.fullstory.com *.bobux.com foursixty.com *.nr-data.net strutfitportalapi.azurewebsites.net www.google-analytics.com prod-00.bobux.solvestack.net *.solvestack.net stats.g.doubleclick.net www.paypal.com www.facebook.com www.youtube.com image-complainer.foursixty.com *.ksearchnet.com bat.bing.com maps.googleapis.com fonts.gstatic.com 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src static.klaviyo.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline';Content-Type: text/html; charset=UTF-8Expires: Wed, 26 May 2021 03:49:20 GMTPragma: cacheX-Content-Type-Options: nosniffX-Debug-Info: eyJyZXRyaWVzIjowfQ==X-Frame-Options: SAMEORIGINX-Platform-Server: i-0284dda4e83ca13f4X-Request-Id: hj5hi47tukdy3rcg3qfdk7mcX-Xss-Protection: 1; mode=blockContent-Encoding: gzipAccept-Ranges: bytesDate: Tue, 25 May 2021 04:20:30 GMTAge: 1869X-Served-By: cache-syd10125-SYD, cache-mdw17363-MDWX-Cache: HIT, HITX-Cache-Hits: 1, 1strict-transport-security: max-age=31536000Cache-Control: no-store, no-cache, must-revalidate, max-age=0Vary: Accept-Encoding,Cookie