Location: https://priceline.com
Location: https://priceline.com
Via: 1.1 varnish
Date: Mon, 29 Jan 2024 05:30:31 GMT
Vary: Origin
Server: iterable-links 08b0
Alt-Svc: h3=":443";ma=86400,h3-29=":443";ma=86400,h3-27=":443";ma=86400
X-Cache: MISS
X-Timer: S1706506231.290745,VS0,VE13
Location: https://priceline.com
Set-Cookie: XSRF-TOKEN=cc67cad66d2d7f221e76994be9507f021548f2cb-1706506231300-ce5429e7289289d1b4af1f7a; SameSite=Lax; Path=/
X-Served-By: cache-lga21983-LGA
Request-Time: 5
X-Cache-Hits: 0
Accept-Ranges: bytes
Content-Length: 0
Referrer-Policy: origin-when-cross-origin, strict-origin-when-cross-origin
X-Xss-Protection: 1; mode=block
X-Content-Type-Options: nosniff
Content-Security-Policy: base-uri 'none'; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub46dd5cf52153d917fc1d5e91ff3a600d&dd-evp-origin=content-security-policy&ddsource=csp-report; frame-ancestors 'self' https://links.iterable.com; object-src 'none'; worker-src 'self' blob:; script-src 'report-sample' 'unsafe-eval' 'unsafe-inline' 'strict-dynamic' https: 'nonce-ix4XRpeqqbX5ZsjjugeC7w=='
X-Permitted-Cross-Domain-Policies: master-only
Via: 1.1 varnish
Date: Mon, 29 Jan 2024 05:30:31 GMT
Vary: Origin
Server: iterable-links b20d
Alt-Svc: h3=":443";ma=86400,h3-29=":443";ma=86400,h3-27=":443";ma=86400
X-Cache: MISS
X-Timer: S1706506231.329663,VS0,VE12
Location: https://priceline.com
Set-Cookie: XSRF-TOKEN=6824686aad50e2e321313b1bf9a9c3d704373b10-1706506231337-0aec79ac3ad321d67bef505a; SameSite=Lax; Path=/
X-Served-By: cache-lga21920-LGA
Request-Time: 3
X-Cache-Hits: 0
Accept-Ranges: bytes
Content-Length: 0
Referrer-Policy: origin-when-cross-origin, strict-origin-when-cross-origin
X-Xss-Protection: 1; mode=block
X-Content-Type-Options: nosniff
Content-Security-Policy: base-uri 'none'; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub46dd5cf52153d917fc1d5e91ff3a600d&dd-evp-origin=content-security-policy&ddsource=csp-report; frame-ancestors 'self' https://links.iterable.com; object-src 'none'; worker-src 'self' blob:; script-src 'report-sample' 'unsafe-eval' 'unsafe-inline' 'strict-dynamic' https: 'nonce-goMOcCFfVQmSDej9TqXmcg=='
X-Permitted-Cross-Domain-Policies: master-only