h3=":443"; ma=86400
no-cache, no-store, must-revalidate, pre-check=0, post-check=0
keep-alive
gzip
block-all-mixed-content; default-src 'self'; base-uri 'self'; form-action 'self' flightbookings.airnewzealand.co.kr flightbookings.airnewzealand.kr flightbookings.airnewzealand.ca flightbookings.airnewzealand.cn flightbookings.airnewzealand.co.nz flightbookings.airnewzealand.co.uk flightbookings.airnewzealand.com.au flightbookings.airnewzealand.com.hk flightbookings.airnewzealand.com.sg flightbookings.airnewzealand.com.tw flightbookings.airnewzealand.com flightbookings.airnewzealand.de flightbookings.airnewzealand.eu flightbookings.airnewzealand.fr flightbookings.airnewzealand.hk flightbookings.airnewzealand.jp flightbookings.airnewzealand.pf flightbookings.airnewzealand.tw flightbookings.airnewzealand.com.cn flightbookings.grabaseat.co.nz flightbookings.airnewzealand.co.jp; script-src 'self' p-airnz.com 'unsafe-inline' 'unsafe-eval' *.googleapis.com *.gstatic.com *.google.com *.ggpht.com *.googleusercontent.com typesquare.com flightbookings.airnewzealand.co.nz player.vimeo.com www.youtube.com s.ytimg.com s.wayin.com xd.wayin.com s.engagesciences.com display.engagesciences.com *.demdex.net www.google-analytics.com analytics.google.com tagmanager.google.com www.googletagmanager.com *.doubleclick.net www.googleadservices.com www.google.com cdn-assets-prod.s3.amazonaws.com *.optimizely.com optimizely-hrd.appspot.com optimizely.s3.amazonaws.com static.hotjar.com script.hotjar.com s.swiftypecdn.com nebula-cdn.kampyle.com screencapture.kampyle.com screencaptue-cdn.kampyle.com https://widget.timatic.iata.org/scripts/iata-timatic-widget-live.js; style-src 'unsafe-inline' p-airnz.com fonts.googleapis.com tagmanager.google.com static.hotjar.com script.hotjar.com s.swiftypecdn.com 'self'; img-src https: data: static.hotjar.com script.hotjar.com; font-src p-airnz.com fonts.googleapis.com fonts.gstatic.com wf.typesquare.com dhm5hy2vn8l0l.cloudfront.net script.hotjar.com data: 'self'; media-src 'self' video.cdnvue.com ; frame-src 'self' *.google.com nz.fltmaps.com player.youku.com v.qq.com player.vimeo.com www.youtube.com airnz.wufoo.com xd.wayin.com display.engagesciences.com *.demdex.net *.doubleclick.net www.googletagmanager.com *.cdn-pci.optimizely.com vars.hotjar.com nebula-cdn.kampyle.com sec.windcave.com uat.windcave.com; connect-src 'self' api.airnz.io api.airnz.ai *.googleapis.com *.google.com *.gstatic.com l.typesquare.com *.demdex.net *.tt.omtrdc.net www.google-analytics.com region1.google-analytics.com region1.analytics.google.com analytics.google.com stats.g.doubleclick.net adservice.google.com *.optimizely.com https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com s.swiftypecdn.com search-api.swiftype.com *.kampyle.com https://widget.timatic.iata.org/api/ sec.windcave.com uat.windcave.com; object-src 'none'; frame-ancestors 'none'; report-uri /csp-report
text/html; charset=UTF-8
Tue, 09 Jan 2024 11:52:13 GMT
Tue, 09 Jan 2024 05:35:51 GMT
geolocation=(self "https://p-airnz.com"), camera=(), fullscreen=(self "https://www.youtube.com"), accelerometer=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), screen-wake-lock=(), sync-xhr=(*), usb=(), web-share=(), clipboard-read=(), clipboard-write=()
strict-origin
nginx
max-age=31536000; includeSubDomains;
Accept-Encoding
1.1 8bb9e89620bf25ebe1ca7fb9ac6e3806.cloudfront.net (CloudFront)
Gzdv7vTvKEv1rCZEzmzYzsh0eaGN5EooRYYy-5gQ52beNUEXX4nwig==
MAN51-P2
Miss from cloudfront
nosniff
SAMEORIGIN
1; mode=block
|