Transfer-Encoding: | chunked |
X-Cache-Hits: | 0, 0 |
x-xss-protection: | 1; mode=block |
x-content-type-options: | nosniff |
etag: | W/"def642f439e3b7f7ad4c7db601e924fc" |
x-ua-compatible: | IE=Edge,chrome=1 |
cache-control: | no-store, max-age=0, private, must-revalidate |
Date: | Fri, 11 Jan 2019 07:54:09 GMT |
referrer-policy: | same-origin |
Age: | 0, 0, 0, 0 |
status: | 200 OK |
X-Cache: | MISS, MISS |
set-cookie: | bev=1547193248_%2F7Xng6enZLj9SFmH; domain=.airbnb.com; path=/; expires=Sun, 10-Jan-2021 07:54:08 GMT; secure, _csrf_token=V4%24.airbnb.com%240iCHW2pWp2U%24Ols6bEB966nl6En-tPFQ62THM2IK-OGRtDp0ii0ADTg%3D; domain=.airbnb.com; path=/; secure, jitney_client_session_id=a2ac006f-87cd-4b59-8e74-df74cf136779; domain=.airbnb.com; path=/; expires=Sat, 12-Jan-2019 07:54:08 GMT; secure, jitney_client_session_created_at=1547193248; domain=.airbnb.com; path=/; expires=Sat, 12-Jan-2019 07:54:08 GMT; secure, jitney_client_session_updated_at=1547193248; domain=.airbnb.com; path=/; expires=Sat, 12-Jan-2019 07:54:08 GMT; secure, _user_attributes=%7B%22curr%22%3A%22USD%22%2C%22guest_exchange%22%3A1.0%2C%22device_profiling_session_id%22%3A%221547193249--ef9320e6fe4723583f122705%22%2C%22giftcard_profiling_session_id%22%3A%221547193249--851da96550cbe2a1026c89d6%22%2C%22reservation_profiling_session_id%22%3A%221547193249--789df4549681d6306d13f20d%22%7D; domain=.airbnb.com; path=/; expires=Mon, 11-Jan-2021 07:54:09 GMT; secure, flags=0; domain=.airbnb.com; path=/; secure, __svt=1013, cereal_exp=2; expires=Tue, 12 Mar 2019 07:54:09 GMT; domain=.airbnb.com; path=/, 856568311=treatment; expires=Tue, 12 Mar 2019 07:54:09 GMT; domain=.airbnb.com; path=/, cache_state=0; domain=.airbnb.com; path=/; Secure |
Accept-Ranges: | bytes, bytes, bytes, bytes |
Strict-Transport-Security: | max-age=10886400; includeSubdomains |
Server: | nginx |
x-envoy-upstream-service-time: | 1017 |
Connection: | keep-alive |
X-Served-By: | cache-bwi5140-BWI, cache-jfk8144-JFK |
link: | ;rel=preload;as=style,;rel=preload;as=style,;rel=preload;as=style,;rel=preload;as=font;type=font/woff2;crossorigin=crossorigin,;rel=preload;as=font;type=font/woff2;crossorigin=crossorigin,;rel=preload;as=font;type=font/woff2;crossorigin=crossorigin,;rel=preload;as=script |
Via: | 1.1 varnish, 1.1 varnish |
content-security-policy: | default-src 'self' https: blob:; child-src * blob:; connect-src 'self' https: wss: *.amap.com *.inspectlet.com *.mapbox.com api.map.baidu.com netverify.com *.netverify.com; font-src 'self' data: *.muscache.com fonts.gstatic.com use.typekit.net; img-src 'self' https: data: *.inspectlet.com *.mapbox.com *.gstatic.com; media-src 'self' https: blob:; script-src 'self' 'unsafe-eval' a0.muscache.com cdn.siftscience.com ss.musthird.com t1.musthird.com bat.bing.com connect.facebook.net www.google-analytics.com www.googleadservices.com tpc.googlesyndication.com www.googletagmanager.com a.cdn.intentmedia.net maps.googleapis.com ajax.googleapis.com *.g.doubleclick.net app.link cdn.branch.io api.branch.io bam.nr-data.net js-agent.newrelic.com sslwidget.criteo.com static.criteo.net dis.criteo.com widget.us.criteo.com *.gbc.criteo.net ethn.io s.yimg.jp api.geetest.com blob: webapi.amap.com restapi.amap.com *.inspectlet.com 'nonce-ab25f866249afb7171cc42d58d59e1' *.mapbox.com *.google.com *.gstatic.com api.map.baidu.com netverify.com *.netverify.com icm.aexp-static.com qicm.americanexpress.com qwww435.americanexpress.com checkout.americanexpress.com www.paypalobjects.com 'sha256-URqFTNitDSE01K1xklErUlKT93/P4FXStf52o8BhcLY=' 'unsafe-inline' 'sha256-A5WddWpudAUrh16ACJsxADjW6qxQr0CN36T3SCcp7Ts=' 'sha256-D9Mz5Ys1Opv52C2fjJU4eS9qDZpG9+Ywz5rQPUyxngQ='; style-src 'self' https: 'unsafe-inline' *.mapbox.com; report-uri /tracking/csp?action=show&controller=rooms&report_only=false&req_uuid=a7b0a8f3-d674-4e61-a8c0-d877a137e89a&version=1a0784e1a0ea2fab743955864589c595b3933963 |
content-encoding: | gzip |
X-Timer: | S1547193248.347828,VS0,VE1034 |
Vary: | Accept-Encoding |
X-Server-Name: | www.airbnb.com |
content-security-policy-report-only: | default-src blob: *; child-src blob: *; connect-src blob: *; font-src 'self' data: *.muscache.com fonts.gstatic.com use.typekit.net; img-src 'self' https: data: *.inspectlet.com; script-src 'self' 'unsafe-eval' webpack.localhost.airbnb.com jira.airbnb.biz *.g.doubleclick.net cdn.siftscience.com ss.musthird.com t1.musthird.com bat.bing.com connect.facebook.net www.google-analytics.com www.googleadservices.com tpc.googlesyndication.com www.googletagmanager.com maps.googleapis.com ajax.googleapis.com app.link cdn.branch.io api.branch.io bam.nr-data.net js-agent.newrelic.com sslwidget.criteo.com static.criteo.net dis.criteo.com widget.us.criteo.com ethn.io blob: webapi.amap.com restapi.amap.com *.inspectlet.com cdn.ampproject.org/v0.js cdn.ampproject.org/v0/ a.alipayobjects.com gw.alipayobjects.com static.t.agrant.cn t.agrantsem.com ditu.google.com *.muscache.cn *.muscache.com ss.musthird.cn www.google.com www.gstatic.com b92.yahoo.co.jp mc.yandex.ru wcs.naver.net static.matterport.com a.cdn.intentmedia.net s.yimg.jp icm.aexp-static.com checkout.americanexpress.com www.paypalobjects.com smartlock.google.com accounts.google.com 'sha256-URqFTNitDSE01K1xklErUlKT93/P4FXStf52o8BhcLY=' 'unsafe-inline' 'sha256-A5WddWpudAUrh16ACJsxADjW6qxQr0CN36T3SCcp7Ts=' 'sha256-D9Mz5Ys1Opv52C2fjJU4eS9qDZpG9+Ywz5rQPUyxngQ='; style-src * blob: 'unsafe-inline'; report-uri /tracking/csp?action=show&controller=rooms&report_only=true&req_uuid=a7b0a8f3-d674-4e61-a8c0-d877a137e89a&version=1a0784e1a0ea2fab743955864589c595b3933963 |
server-timing: | total;dur=1013 |
edge-control: | no-store |
x-frame-options: | SAMEORIGIN |
Content-Type: | text/html; charset=utf-8 |