Transfer-Encoding: chunked
Connection: keep-alive
X-Permitted-Cross-Domain-Policies: master-only
X-Page-Speed: 1.13.35.2-0
Set-Cookie: symfony=4gf7re803be0npsrm6f8676qo1; path=/; secure; HttpOnly
Strict-Transport-Security: max-age=31536000; includeSubDomains
Vary: Accept-Encoding
HTTP/1.1 200 OK
Content-Security-Policy: default-src 'self' *.gazkazan-kazan.hu *.hotjar.com *.wirecard.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.gazkazan-kazan.hu *.wirecard.com *.google.hu *.google-analytics.com *.facebook.net *.youtube.com *.google.com *.googlevideo.com *.gstatic.com *.facebook.com *.googleapis.com *.googleadservices.com *.doubleclick.net *.hotjar.com *.arukereso.hu; img-src 'self' *.gazkazan-kazan.hu *.google-analytics.com *.google.hu blob: data: *.gazkazan-kazan.hu *.google-analytics.com *.facebook.net *.youtube.com *.google.com *.googlevideo.com *.gstatic.com *.facebook.com *.googleapis.com *.googleadservices.com *.doubleclick.net *.hotjar.com *.arukereso.hu; style-src 'self' 'unsafe-inline' *.gazkazan-kazan.hu *.facebook.net *.youtube.com *.google.com *.googlevideo.com *.gstatic.com *.facebook.com *.googleapis.com *.googleadservices.com *.doubleclick.net *.hotjar.com *.arukereso.hu; font-src 'self' data: *.gazkazan-kazan.hu *.facebook.net *.youtube.com *.google.com *.googlevideo.com *.gstatic.com *.facebook.com *.googleapis.com *.googleadservices.com *.doubleclick.net *.hotjar.com *.arukereso.hu; child-src 'self' *.gazkazan-kazan.hu *.wirecard.com *.facebook.net *.youtube.com *.google.com *.googlevideo.com *.gstatic.com *.facebook.com *.googleapis.com *.googleadservices.com *.doubleclick.net *.hotjar.com *.arukereso.hu; object-src 'self'
Content-Type: text/html; charset=utf-8
Date: Tue, 20 Feb 2018 18:46:48 GMT
Pragma: no-cache
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
Cache-Control: max-age=0, no-cache, no-store
X-Content-Type-Options: nosniff
Server: webserver