HTTP/1.1 200 Set-Cookie: dtCookie=v_4_srv_48_sn_756222EB6D50CC23910E7B5961299E24_perc_46943_ol_0_mul_3_app-3A060f8e695ee92341_1_rcs-3Acss_0; Path=/; Domain=.myprotein.com; secureX-OneAgent-JS-Injection: trueServer-Timing: dtRpid;desc="636083002", dtSInfo;desc="0"Cache-Control: private, max-age=0, no-cache, no-store, must-revalidatePragma: no-cacheExpires: Thu, 01 Jan 1970 00:00:00 GMTX-Frame-Options: SAMEORIGINX-Content-Type-Options: nosniffSet-Cookie: JSESSIONID=D6AFD4ED6E46594734DFFCEDDDA6C5F2; Path=/; Secure; HttpOnlySet-Cookie: chumewe_user=fc016636-d834-4f05-8c01-12bd9e29eb3c; Version=1; Domain=.myprotein.com; Path=/; Max-Age=157784630; Expires=Thu, 21-Jan-2027 18:25:27 GMT; SameSite=None; SecureSet-Cookie: chumewe_sess=43e9e4f0-ae8b-42b8-ad08-f4f2c4045e29; Version=1; Domain=.myprotein.com; Path=/; Max-Age=14400; Expires=Fri, 21-Jan-2022 17:21:37 GMT; SameSite=None; SecureSet-Cookie: locale_V6=en_GB; Version=1; Domain=.myprotein.com; Path=/; Max-Age=31556926; Expires=Sat, 21-Jan-2023 19:10:23 GMT; SameSite=None; SecureSet-Cookie: csrf_token=63154099302314015034; Version=1; Path=/; SameSite=None; HttpOnly; SecureContent-Security-Policy-Report-Only: child-src 'self' https://www.googletagmanager.com https://*.liveperson.net https://cdn.appdynamics.com https://*.lpsnmedia.net https://www.facebook.com https://connect.facebook.net https://*.google.com https://widget.trustpilot.com https://*.doubleclick.net https://www.youtube.com https://*.zenaps.com https://*.criteo.com https://static.criteo.net https://tpc.googlesyndication.com https://wb.messengerpeople.com https://ct.pinterest.com https://*.recaptcha.net https://*.snapchat.com https://*.hotjar.com https://*.akamaihd.net https://*.translate.naver.net https://ln-rules.rewardstyle.com https://www.pinterest.com https://www.pinterest.co.uk https://app.qubit.com; connect-src 'self' https://*.thcdn.com https://*.ingest.sentry.io https://*.pingdom.net https://*.doubleclick.net https://*.google-analytics.com https://capture.trackjs.com https://fp.zenaps.com https://www.facebook.com https://*.google.com https://*.thehut.net https://ct.pinterest.com https://services.postcodeanywhere.co.uk https://*.akamaihd.net https://*.sciencebehindecommerce.com https://*.hotjar.com wss://*.hotjar.com https://*.googleapis.com https://*.trustpilot.com https://*.pinterest.com https://*.doubleclick.net https://*.bing.com https://connect.facebook.net https://*.baidu.com https://*.parcellab.com https://analytics.tiktok.com https://*.google.co.uk https://tr.snapchat.com https://*.qubit.com https://*.qubitproducts.com; default-src 'none'; font-src 'self' data: https://*.thcdn.com https://fp.zenaps.com https://cdnjs.cloudflare.com https://fonts.gstatic.com https://fonts.googleapis.com https://static.thgcdn.cn; form-action 'self' https://www.facebook.com https://checkout.myprotein.com https://connect.facebook.net https://m.myprotein.com https://www.myprotein.com https://ct.pinterest.com https://*.snapchat.com; img-src 'self' data: https://*.thcdn.com https://col.eum-appdynamics.com https://usage.trackjs.com https://*.lpsnmedia.net https://*.doubleclick.net https://www.google-analytics.com https://*.google.com https://cx.atdmt.com https://www.zenaps.com https:; manifest-src 'none' 'self'; media-src 'self' https://*.thcdn.com https://*.lpsnmedia.net https://static.thgcdn.cn; object-src 'self' https://*.thcdn.com https://www.youtube.com; report-uri https://csp.thehut.net/cspReport.txt; script-src 'self' 'unsafe-eval' 'unsafe-inline' data: https://*.thcdn.com https://*.thehut.net https://rum-static.pingdom.net https://*.liveperson.net https://*.lpsnmedia.net https://*.doubleclick.net https://static.cdn-apple.com https://*.liveperson.com https://google.com https://*.googletagmanager.com https://cdnjs.cloudflare.com https://fp.zenaps.com https://www.youtube.com https://*.google-analytics.com https://*.google.com https://connect.facebook.net https://bat.bing.com https://widget.trustpilot.com https://s.ytimg.com https://*.googletagservices.com https://*.google.co.uk https://*.googleapis.com https://ssl.trustpilot.com https://www.facebook.com https://*.googleadservices.com https://*.gstatic.cn https://*.gstatic.com https://www.dwin1.com https://cdn.trackjs.com https://seal.digicert.com https://remote.captcha.com https://*.criteo.com https://static.criteo.net https://*.googlesyndication.com https://static.ads-twitter.com https://*.twitter.com https://s.pinimg.com https://*.akamaihd.net https://*.recaptcha.net https://*.sciencebehindecommerce.com https://sc-static.net https://*.hotjar.com https://*.microsofttranslator.com https://*.trustpilot.com https://www.googleadservices.com https://*.translate.naver.net https://*.doubleclick.net https://ln-rules.rewardstyle.com https://twitter.com https://tpc.googlesyndication.com https://*.baidu.com https://www.google.com https://google.co.uk https://lantern.roeyecdn.com https://lantern.roeye.com https://analytics.tiktok.com https://*.ibytedtos.com https://static.thgcdn.cn https://static.goqubit.com https://*.qubit.com; style-src 'self' 'unsafe-inline' https://*.thcdn.com https://*.google.com https://*.googleapis.com https://fp.zenaps.com https://cdnjs.cloudflare.com https://*.googleapis.com https://*.translate.naver.net https://*.microsofttranslator.com https://cdn.parcellab.com https://static.thgcdn.cn; upgrade-insecure-requests; report-to report-endpointReferrer-Policy: unsafe-urlX-XSS-Protection: 1; mode=block; report=/xssProtection.txtStrict-Transport-Security: max-age=31536000; includeSubDomains; preloadReport-To: {"group":"report-endpoint","max_age":86400,"endpoints":[{"url":"https://csp.thehut.net/cspReport.txt","priority":1,"weight":1}],"include_subdomains":true}vary: accept-encodingContent-Encoding: gzipContent-Type: text/html;charset=UTF-8Transfer-Encoding: chunkedDate: Fri, 21 Jan 2022 13:21:37 GMTSet-Cookie: NSC_mc_wtsw_efgbvmu_xfctsw_8010_G=ffffffff09031fc645525d5f4f58455e445a4a42297a;expires=Fri, 21-Jan-2022 16:21:37 GMT;path=/;secure;httponly