.techlab-cdn.com *.instagram.com *.akamaihd.net *.akstat.io *.cloudfront.net *.cognigy.cloud *.googleapis.com *.gstatic.com *.sheerid.com *.meili.travel bat.bing.com *.dwin1.com lhopa01.custhelp.com 'unsafe-inline' 'unsafe-eval'; object-src 'none'; worker-src blob: *.lufthansa.com; strict-transport-security: max-age=31536000 ; preload access-control-allow-origin: https://www.miles-and-more.com vary: Accept-Encoding, Accept-Encoding, Origin X-Firefox-Spdy: h2