HTTP/1.1 200 OKServer: nginxContent-Type: text/html; charset=utf-8Vary: Accept-EncodingStatus: 200 OKLink: ;rel=preload;as=style,;rel=preload;as=style,;rel=preload;as=style,;rel=preload;as=style,;rel=preload;as=font;type=font/woff2;crossorigin=crossorigin,;rel=preload;as=font;type=font/woff2;crossorigin=crossorigin,;rel=preload;as=font;type=font/woff2;crossorigin=crossorigin,;rel=preload;as=scriptX-Frame-Options: SAMEORIGINReferrer-Policy: same-originX-UA-Compatible: IE=Edge,chrome=1ETag: W/"f93b626405d002052827baff77703f38"Content-Security-Policy: default-src 'self' https: blob:; child-src *; connect-src 'self' https: wss: *.amap.com *.inspectlet.com; font-src 'self' data: *.muscache.com fonts.gstatic.com use.typekit.net; img-src 'self' https: data: *.inspectlet.com; media-src 'self' https:; script-src 'self' 'unsafe-eval' a0.muscache.com cdn.siftscience.com ss.musthird.com t1.musthird.com bat.bing.com connect.facebook.net www.google-analytics.com www.googleadservices.com tpc.googlesyndication.com www.googletagmanager.com a.cdn.intentmedia.net maps.googleapis.com ajax.googleapis.com *.g.doubleclick.net www.google.com www.gstatic.com app.link cdn.branch.io bam.nr-data.net js-agent.newrelic.com sslwidget.criteo.com static.criteo.net dis.criteo.com widget.us.criteo.com *.gbc.criteo.net ethn.io s.yimg.jp api.geetest.com blob: webapi.amap.com restapi.amap.com *.inspectlet.com 'sha256-Gn3R3CfqodkNUs+C4gXoCllPFSnBVuhJSWkVuIlhYzc=' 'unsafe-inline' 'sha256-rfTud2kTm0UjtJ6PqxcrkglfrUD4H8WCcS9mCs6PJ5s=' 'sha256-D9Mz5Ys1Opv52C2fjJU4eS9qDZpG9+Ywz5rQPUyxngQ='; style-src 'self' https: 'unsafe-inline'; report-uri /tracking/csp?action=show&controller=homepages&report_only=false&req_uuid=bfdb2db6-93b3-4b69-a5be-a71ce52676de&version=a41c1ad29237d7c2f30a9395a90e7f6aa4c15c48Content-Security-Policy-Report-Only: default-src blob: *; connect-src blob: *; font-src 'self' data: *.muscache.com fonts.gstatic.com use.typekit.net; img-src 'self' https: data: *.inspectlet.com; script-src 'self' 'unsafe-eval' webpack.localhost.airbnb.com jira.airbnb.biz *.g.doubleclick.net cdn.siftscience.com ss.musthird.com t1.musthird.com bat.bing.com connect.facebook.net www.google-analytics.com www.googleadservices.com tpc.googlesyndication.com www.googletagmanager.com maps.googleapis.com ajax.googleapis.com app.link cdn.branch.io bam.nr-data.net js-agent.newrelic.com sslwidget.criteo.com static.criteo.net dis.criteo.com widget.us.criteo.com ethn.io blob: webapi.amap.com restapi.amap.com *.inspectlet.com cdn.ampproject.org/v0.js cdn.ampproject.org/v0/ a.alipayobjects.com gw.alipayobjects.com static.t.agrant.cn t.agrantsem.com ditu.google.com *.muscache.cn *.muscache.com ss.musthird.cn www.google.com www.gstatic.com b92.yahoo.co.jp mc.yandex.ru wcs.naver.net a.cdn.intentmedia.net s.yimg.jp 'sha256-Gn3R3CfqodkNUs+C4gXoCllPFSnBVuhJSWkVuIlhYzc=' 'unsafe-inline' 'sha256-rfTud2kTm0UjtJ6PqxcrkglfrUD4H8WCcS9mCs6PJ5s=' 'sha256-D9Mz5Ys1Opv52C2fjJU4eS9qDZpG9+Ywz5rQPUyxngQ='; style-src * blob: 'unsafe-inline'; report-uri /tracking/csp?action=show&controller=homepages&report_only=true&req_uuid=bfdb2db6-93b3-4b69-a5be-a71ce52676de&version=a41c1ad29237d7c2f30a9395a90e7f6aa4c15c48X-Content-Type-Options: nosniffX-XSS-Protection: 1; mode=blockContent-Encoding: gzipStrict-Transport-Security: max-age=10886400; includeSubdomainsX-Server-Name: www.airbnb.comContent-Length: 134308Cache-Control: public, max-age=185Date: Tue, 27 Mar 2018 14:18:45 GMTConnection: keep-aliveSet-Cookie: dtc_exp=27; expires=Sat, 26-May-2018 14:18:45 GMT; path=/; domain=.airbnb.comSet-Cookie: 3905031f7=treatment; expires=Sat, 26-May-2018 14:18:45 GMT; path=/; domain=.airbnb.comSet-Cookie: b3b78300e=treatment; expires=Sat, 26-May-2018 14:18:45 GMT; path=/; domain=.airbnb.comSet-Cookie: cache_state=1; path=/; Domain=.airbnb.com; Secure;