HTTP/1.1 301 Moved Permanently
Content-Length: 142
Content-Type: text/html; charset=UTF-8
Location: https://www.coop.se
X-Server-Name: 00416
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
Date: Tue, 02 Aug 2022 08:55:27 GMT
HTTP/1.1 200 OK
Date: Tue, 02 Aug 2022 08:55:28 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
Access-Control-Expose-Headers: Request-Context
Cache-Control: private
Set-Cookie: ASP.NET_SessionId=d2xqropf5gt1r3ns4igk1nc2; path=/; secure; HttpOnly; SameSite=Lax
Set-Cookie: coop-storeContext=eyJ6aXBDb2RlIjpudWxsLCJwcm9kdWN0aW9uVW5pdElkIjoiMDE2MDAxIiwicGlja3VwUG9pbnRJZCI6bnVsbCwic3RvcmVOYW1lIjpudWxsfQ==; expires=Wed, 02-Aug-2023 08:55:28 GMT; path=/; secure
Set-Cookie: ARRAffinity=22463f9c44958668ca8042e48ed0e0b33ce6228fef3d569541c9cfbbd47fb4f3;Path=/;HttpOnly;Secure;Domain=www.coop.se
Set-Cookie: ARRAffinitySameSite=22463f9c44958668ca8042e48ed0e0b33ce6228fef3d569541c9cfbbd47fb4f3;Path=/;HttpOnly;SameSite=None;Secure;Domain=www.coop.se
Vary: Accept-Encoding
X-Content-Security-Policy: default-src 'self'; media-src 'self' static.zdassets.com res.cloudinary.com emp.jobylon.com cdn.jobylon.com *.jobylon.com; frame-ancestors 'self' *.flysas.com; script-src 'self' data: 'unsafe-inline' 'unsafe-eval' *.googleapis.com puzzleplayz.com chat.kindlycdn.com cdn.spinnaker-js.com develop--coopcover.netlify.app coopcover.netlify.app *.dynamicyield.eu *.dynamicyield.com res.cloudinary.com *.richrelevance.com www.google-analytics.com www.googletagmanager.com *.googleapis.com *.pingdom.net *.facebook.com connect.facebook.net *.twitter.com *.google.com *.jobylon.com *.abtasty.com www.nordicchoicehotels.com *.flysas.com extads.net m.addthisedge.com m.addthis.com s7.addthis.com assets.juicer.io *.cloudfront.net track.adform.net *.fls.doubleclick.net nowinteract-nowinteractnordi.netdna-ssl.com *.easyresearch.se *.zendesk.com *.zopim.com wss://*.zopim.com *.zopim.io ve1storasstst.blob.core.windows.net *.zdassets.com cdnjs.cloudflare.com www.sj.se adtr.io *.hotjar.com 'unsafe-eval' quiz.millionmind.com snap.licdn.com px.ads.linkedin.com www.linkedin.com chimpstatic.com *.millionmind.com js.klarna.com *.upscope.io *.coop.se *.payex.com consentmanager.mgr.consensu.org cdn.consentmanager.mgr.consensu.org cdn.consentmanager.net www.googleoptimize.com www.googleadservices.com scripts.cloud.betala.coop.se *.consentmanager.net; connect-src 'self' wss://*.coop.se:* wss://*.kf.local:* maps.googleapis.com app.getsentry.com cdn.spinnaker-js.com *.dynamicyield.eu *.dynamicyield.com emp.jobylon.com cdn.jobylon.com *.jobylon.com *.pingdom.net *.abtasty.com ve1appseventssb.servicebus.windows.net apil1.spinnaker-js.com m.addthis.com s7.addthis.com www.juicer.io assets.juicer.io *.108proxy.se *.54proxy.se www.google-analytics.com www.googletagmanager.com tagmanager.google.com *.zendesk.com *.zopim.com wss://*.zopim.com *.zopim.io *.facebook.com connect.facebook.net *.zdassets.com cdnjs.cloudflare.com *.richrelevance.com *.hotjar.com:* wss://*.hotjar.com track.adtraction.com vc.hotjar.io eu.klarnaevt.com stats.g.doubleclick.net www.nordicchoicehotels.com dc.services.visualstudio.com *.upscope.io wss://*.upscope.io *.api.coop.se *.unboxai.org *.betala.coop.se *.coop.se consentmanager.mgr.consensu.org cdn.consentmanager.mgr.consensu.org www.google.com www.google.se googleads.g.doubleclick.net api.production.coop.onlobster.net delivery.consentmanager.net direct.dy-api.eu zendesk-eu.my.sentry.io; style-src 'self' 'unsafe-inline' *.dynamicyield.eu *.dynamicyield.com emp.jobylon.com cdn.jobylon.com *.jobylon.com *.abtasty.com *.pingdom.net assets.juicer.io tagmanager.google.com fonts.googleapis.com optimize.google.com *.easyresearch.se *.zendesk.com *.zopim.com *.zopim.io *.zdassets.com cdnjs.cloudflare.com consentmanager.mgr.consensu.org cdn.consentmanager.mgr.consensu.org; img-src 'self' data: cdn.spinnaker-js.com api.production.coop.onlobster.net aicomms-themes.s3-eu-west-1.amazonaws.com s3.eu-west-2.amazonaws.com aicomms-themes.s3.eu-west-1.amazonaws.com *.dynamicyield.eu *.dynamicyield.com *.jobylon.com *.pingdom.net *.zendesk.com *.abtasty.com *.gstatic.com api.hitta.se scontent.cdninstagram.com www.google.com www.google.se *.google-analytics.com *.googletagmanager.com tagmanager.google.com res.cloudinary.com *.cloudfront.net *.facebook.com stats.g.doubleclick.net track.adform.net *.fls.doubleclick.net *.easyresearch.se *.zendesk.com *.zopim.com wss://*.zopim.com *.zopim.io *.zdassets.com cdnjs.cloudflare.com *.googleapis.com assets.juicer.io scontent.cdninstagram.com *.hotjar.com *.ggpht.com track.adtraction.com cx.atdmt.com eu.klarnaevt.com *.coop.se delivery.consentmanager.net cdn.consentmanager.net googleads.g.doubleclick.net www.googleadservices.com 'self' blob: s3-eu-west-1.amazonaws.com consentmanager.mgr.consensu.org cdn.consentmanager.mgr.consensu.org; font-src 'self' data: *.dynamicyield.eu *.dynamicyield.com emp.jobylon.com cdn.jobylon.com *.jobylon.com static.juicer.io fonts.gstatic.com tagmanager.google.com *.zendesk.com *.zopim.com wss://*.zopim.com *.zopim.io *.zdassets.com *.hotjar.com consentmanager.mgr.consensu.org cdn.consentmanager.mgr.consensu.org; frame-src 'self' puzzleplayz.com emp.jobylon.com cdn.jobylon.com *.jobylon.com accounts.google.com optimize.google.com *.flysas.com app.ecoonline.com www.nordicchoicehotels.com recruit.visma.com www.recruit.visma.com www.aditrorecruit.com *.twitter.com www.youtube.com *.facebook.com c1.adform.net s7.addthis.com track.adform.net *.fls.doubleclick.net *.easyresearch.se *.abtasty.com *.zendesk.com *.zopim.com wss://*.zopim.com *.zopim.io www.google.com ve1storasstst.blob.core.windows.net *.zdassets.com cdnjs.cloudflare.com www.sj.se *.hotjar.com *.tradedoubler.com quiz.millionmind.com *.millionmind.com payment.medmera.se api-test.betala.coop.se js.klarna.com foodlab2b.appspot.com *.upscope.io memberpayment.betala.coop.se consentmanager.mgr.consensu.org cdn.consentmanager.mgr.consensu.org medmerabank.coop.se stage.medmera.se sustainability.production.coop.onlobster.net *.payex.com; base-uri 'self' *.coop.se *.kf.local optimize.google.com;
Content-Security-Policy: default-src 'self'; media-src 'self' static.zdassets.com res.cloudinary.com emp.jobylon.com cdn.jobylon.com *.jobylon.com; frame-ancestors 'self' *.flysas.com; script-src 'self' data: 'unsafe-inline' 'unsafe-eval' *.googleapis.com puzzleplayz.com chat.kindlycdn.com cdn.spinnaker-js.com develop--coopcover.netlify.app coopcover.netlify.app *.dynamicyield.eu *.dynamicyield.com res.cloudinary.com *.richrelevance.com www.google-analytics.com www.googletagmanager.com *.googleapis.com *.pingdom.net *.facebook.com connect.facebook.net *.twitter.com *.google.com *.jobylon.com *.abtasty.com www.nordicchoicehotels.com *.flysas.com extads.net m.addthisedge.com m.addthis.com s7.addthis.com assets.juicer.io *.cloudfront.net track.adform.net *.fls.doubleclick.net nowinteract-nowinteractnordi.netdna-ssl.com *.easyresearch.se *.zendesk.com *.zopim.com wss://*.zopim.com *.zopim.io ve1storasstst.blob.core.windows.net *.zdassets.com cdnjs.cloudflare.com www.sj.se adtr.io *.hotjar.com 'unsafe-eval' quiz.millionmind.com snap.licdn.com px.ads.linkedin.com www.linkedin.com chimpstatic.com *.millionmind.com js.klarna.com *.upscope.io *.coop.se *.payex.com consentmanager.mgr.consensu.org cdn.consentmanager.mgr.consensu.org cdn.consentmanager.net www.googleoptimize.com www.googleadservices.com scripts.cloud.betala.coop.se *.consentmanager.net; connect-src 'self' wss://*.coop.se:* wss://*.kf.local:* maps.googleapis.com app.getsentry.com cdn.spinnaker-js.com *.dynamicyield.eu *.dynamicyield.com emp.jobylon.com cdn.jobylon.com *.jobylon.com *.pingdom.net *.abtasty.com ve1appseventssb.servicebus.windows.net apil1.spinnaker-js.com m.addthis.com s7.addthis.com www.juicer.io assets.juicer.io *.108proxy.se *.54proxy.se www.google-analytics.com www.googletagmanager.com tagmanager.google.com *.zendesk.com *.zopim.com wss://*.zopim.com *.zopim.io *.facebook.com connect.facebook.net *.zdassets.com cdnjs.cloudflare.com *.richrelevance.com *.hotjar.com:* wss://*.hotjar.com track.adtraction.com vc.hotjar.io eu.klarnaevt.com stats.g.doubleclick.net www.nordicchoicehotels.com dc.services.visualstudio.com *.upscope.io wss://*.upscope.io *.api.coop.se *.unboxai.org *.betala.coop.se *.coop.se consentmanager.mgr.consensu.org cdn.consentmanager.mgr.consensu.org www.google.com www.google.se googleads.g.doubleclick.net api.production.coop.onlobster.net delivery.consentmanager.net direct.dy-api.eu zendesk-eu.my.sentry.io; style-src 'self' 'unsafe-inline' *.dynamicyield.eu *.dynamicyield.com emp.jobylon.com cdn.jobylon.com *.jobylon.com *.abtasty.com *.pingdom.net assets.juicer.io tagmanager.google.com fonts.googleapis.com optimize.google.com *.easyresearch.se *.zendesk.com *.zopim.com *.zopim.io *.zdassets.com cdnjs.cloudflare.com consentmanager.mgr.consensu.org cdn.consentmanager.mgr.consensu.org; img-src 'self' data: cdn.spinnaker-js.com api.production.coop.onlobster.net aicomms-themes.s3-eu-west-1.amazonaws.com s3.eu-west-2.amazonaws.com aicomms-themes.s3.eu-west-1.amazonaws.com *.dynamicyield.eu *.dynamicyield.com *.jobylon.com *.pingdom.net *.zendesk.com *.abtasty.com *.gstatic.com api.hitta.se scontent.cdninstagram.com www.google.com www.google.se *.google-analytics.com *.googletagmanager.com tagmanager.google.com res.cloudinary.com *.cloudfront.net *.facebook.com stats.g.doubleclick.net track.adform.net *.fls.doubleclick.net *.easyresearch.se *.zendesk.com *.zopim.com wss://*.zopim.com *.zopim.io *.zdassets.com cdnjs.cloudflare.com *.googleapis.com assets.juicer.io scontent.cdninstagram.com *.hotjar.com *.ggpht.com track.adtraction.com cx.atdmt.com eu.klarnaevt.com *.coop.se delivery.consentmanager.net cdn.consentmanager.net googleads.g.doubleclick.net www.googleadservices.com 'self' blob: s3-eu-west-1.amazonaws.com consentmanager.mgr.consensu.org cdn.consentmanager.mgr.consensu.org; font-src 'self' data: *.dynamicyield.eu *.dynamicyield.com emp.jobylon.com cdn.jobylon.com *.jobylon.com static.juicer.io fonts.gstatic.com tagmanager.google.com *.zendesk.com *.zopim.com wss://*.zopim.com *.zopim.io *.zdassets.com *.hotjar.com consentmanager.mgr.consensu.org cdn.consentmanager.mgr.consensu.org; frame-src 'self' puzzleplayz.com emp.jobylon.com cdn.jobylon.com *.jobylon.com accounts.google.com optimize.google.com *.flysas.com app.ecoonline.com www.nordicchoicehotels.com recruit.visma.com www.recruit.visma.com www.aditrorecruit.com *.twitter.com www.youtube.com *.facebook.com c1.adform.net s7.addthis.com track.adform.net *.fls.doubleclick.net *.easyresearch.se *.abtasty.com *.zendesk.com *.zopim.com wss://*.zopim.com *.zopim.io www.google.com ve1storasstst.blob.core.windows.net *.zdassets.com cdnjs.cloudflare.com www.sj.se *.hotjar.com *.tradedoubler.com quiz.millionmind.com *.millionmind.com payment.medmera.se api-test.betala.coop.se js.klarna.com foodlab2b.appspot.com *.upscope.io memberpayment.betala.coop.se consentmanager.mgr.consensu.org cdn.consentmanager.mgr.consensu.org medmerabank.coop.se stage.medmera.se sustainability.production.coop.onlobster.net *.payex.com; base-uri 'self' *.coop.se *.kf.local optimize.google.com;
Request-Context: appId=cid-v1:e38f30c4-2c1c-4cbf-9349-e3e878f5ed8d
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
CF-Cache-Status: DYNAMIC
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
CF-RAY: 734598411c11f14e-ARN
Set-Cookie: _tpc_persistance_cookie=!c/CZiakYo/8rFsK8EOda6AVGp4P79f3uvVryuZOX2SAGMaRzJNBdi8zN+p/A85I6Kq+Ba7g49/GEyRg=; path=/; Httponly; Secure
Strict-Transport-Security: max-age=14515200
Set-Cookie: BBN013985a8=0135ab579a0284adb97d44dbfb55b4e7ce96bc9a33e6db15e0c14082650b144ce219a535fd13bd9fc0ae16252557f1e2573326270dd2b1249f52851da277059f733b22f278416920060817674c8cf979ac103c170446375454d6e65c3db14a845f1d35018b0594b452cd841a2b2590f2070e34ac1d6889acce0af4ce5a5f21fa39475b9ae9; Path=/; Domain=.www.coop.se; Secure; HTTPOnly
Transfer-Encoding: chunked
|