identity,gzip
no-cache, no-store
gzip
base-uri 'self' ; child-src https://www.dropbox.com/static/serviceworker/ blob: ; connect-src https://* ws://127.0.0.1:*/ws wss://dsimports.dropbox.com/ ; default-src 'none' ; font-src https://* data: ; form-action 'self' https://www.dropbox.com/ https://dl-web.dropbox.com/ https://photos.dropbox.com/ https://paper.dropbox.com/ https://showcase.dropbox.com/ https://www.hellofax.com/ https://app.hellofax.com/ https://www.hellosign.com/ https://app.hellosign.com/ https://docsend.com/ https://www.docsend.com/ https://help.dropbox.com/ https://navi.dropbox.jp/ https://a.sprig.com/ https://selfguidedlearning.dropboxbusiness.com/ https://instructorledlearning.dropboxbusiness.com/ https://sales.dropboxbusiness.com/ https://accounts.google.com/ https://api.login.yahoo.com/ https://login.yahoo.com/ https://experience.dropbox.com/ https://pal-test.adyen.com https://2e83413d8036243b-Dropbox-pal-live.adyenpayments.com/ https://onedrive.live.com/picker ; frame-src https://* carousel: dbapi-6: dbapi-7: dbapi-8: dropbox-client: itms-apps: itms-appss: ; img-src https://* data: blob: ; media-src https://* blob: ; object-src 'self' https://cfl.dropboxstatic.com/static/ https://www.dropboxstatic.com/static/ ; report-uri https://www.dropbox.com/csp_log?policy_name=metaserver-whitelist ; script-src 'unsafe-eval' https://www.dropbox.com/static/api/ https://www.dropbox.com/page_success/ https://cfl.dropboxstatic.com/static/ https://www.dropboxstatic.com/static/ https://accounts.google.com/gsi/client https://canny.io/sdk.js 'nonce-vjlzVYU+sZalOL7lrrve' ; style-src https://* 'unsafe-inline' 'unsafe-eval' ; worker-src https://www.dropbox.com/static/serviceworker/ https://www.dropbox.com/encrypted_folder_download/service_worker.js blob:, report-uri https://www.dropbox.com/csp_log?policy_name=metaserver-dynamic ; script-src 'unsafe-eval' 'strict-dynamic' 'nonce-vjlzVYU+sZalOL7lrrve' 'nonce-btEHu09J/4PYdiG0/UH6'
application/json
Wed, 10 Jan 2024 05:09:22 GMT
strict-origin-when-cross-origin
envoy
gvc=NzM4NTM1ODkxOTQzMDk2MDk3MzEyNDI0NDc5MjY4NzM3MDA5MzQ%3D; expires=Mon, 08 Jan 2029 05:09:23 GMT; HttpOnly; Path=/; SameSite=None; Secure, t=blqJoU3_W3IzyIKbsFNJQNHI; Domain=dropbox.com; expires=Sat, 09 Jan 2027 05:09:22 GMT; HttpOnly; Path=/; SameSite=None; Secure, __Host-js_csrf=blqJoU3_W3IzyIKbsFNJQNHI; expires=Sat, 09 Jan 2027 05:09:22 GMT; Path=/; SameSite=None; Secure, __Host-ss=D74uGjP5pc; expires=Sat, 09 Jan 2027 05:09:22 GMT; HttpOnly; Path=/; SameSite=Strict; Secure, locale=en; Domain=dropbox.com; expires=Mon, 08 Jan 2029 05:09:23 GMT; Path=/; SameSite=None; Secure
max-age=31536000; includeSubDomains, max-age=31536000; includeSubDomains
chunked
Accept-Encoding
nosniff
a3570ec3b35e436ba10d13eba0998df0
far_remote
DENY
none
1; mode=block
|