Cache-Control: private, s-maxage=0 Content-Length: 41303 Content-Security-Policy: default-src none;frame-src 'self' *.stripe.com *.braintreegateway.com *.youtube.com http://www.youtube.com/embed/ *.facebook.com https://airbnb.massrel.io fb://*;script-src 'self' https://s.ytimg.com https://www.youtube.com/player_api https://api.flickr.com/services/rest/ cdn.mxpnl.com *.stripe.com *.google-analytics.com *.facebook.net *.newrelic.com *.nr-data.net *.braintreegateway.com https://platform.massrelevance.com airbnbopen.us14.list-manage.com 'unsafe-eval' 'unsafe-inline';style-src 'self' 'unsafe-inline';img-src 'self' endpoint896797.azureedge.net https://*.msecnd.net https://airbnb-vod.akamaized.net https://a0.muscache.com *.ytimg.com https://upload.wikimedia.org https://*.staticflickr.com *.stripe.com *.google-analytics.com *.facebook.com *.muscache.com data:;font-src 'self' data:;media-src 'self' endpoint896797.azureedge.net https://*.msecnd.net https://airbnb-vod.akamaized.net https://a0.muscache.com;connect-src 'self' api.mixpanel.com *.sandbox.braintreegateway.com *.braintreegateway.com www.googleapis.com airbnbopen.us14.list-manage.com;form-action 'self'; Content-Type: text/html; charset=utf-8 Date: Thu, 05 Oct 2017 10:32:12 GMT Strict-Transport-Security: max-age=10886400; includeSubDomains; preload