
Balacertar |

If you are not signed in, going to paizo.com only renders an error message with a few JSON data.
Sorry, the website is currently offline.
Sorry, the website is currently offline.
[ { "src": "CMS", "msg": { "status": 200, "statusText": "OK" }, "timestamp": 1600248515358 }, { "src": "CMS", "msg": { "status": 200, "statusText": "OK" }, "timestamp": 1600248515391 }, { "src": "API/accounts/getHeader", "msg": { "status": 200, "statusText": "OK" }, "timestamp": 1600248515650 }, { "src": "api/store/getCart", "msg": { "status": 404, "statusText": "Apple" }, "timestamp": 1600248515735 } ]
If you read this on time, do not sign out or you won't be able to get back into the website.
The best way to reproduce is opening paizo.com in a new private window.
Both tested on Firefox and Chrome Desktop versions.
Request URL: https://paizo.com/
Request Method: GET
Status Code: 503
Remote Address: 52.88.107.157:443
Referrer Policy: no-referrer-when-downgrade
RESPONSE HEADERS
accept-ranges: none
content-encoding: gzip
content-security-policy: default-src 'self' *.paizo.com; img-src 'self' *.paizo.com *.kc-usercontent.com *.ytimg.com; connect-src 'self' https://*.paizo.com https://*.kontent.ai; font-src 'self' https://fonts.gstatic.com https://*.typekit.net; frame-src *.paizo.com *.youtube.com; script-src 'self' 'self' 'unsafe-inline' 'unsafe-eval' https://*.paizo.com https://cdnjs.cloudflare.com https://cdn.jsdelivr.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://*.typekit.net
content-type: text/html; charset=utf-8
date: Wed, 16 Sep 2020 09:35:22 GMT
expect-ct: max-age=0
referrer-policy: no-referrer
status: 503
strict-transport-security: max-age=15552000; includeSubDomains
vary: Accept-Encoding
x-content-type-options: nosniff
x-dns-prefetch-control: off
x-download-options: noopen
x-frame-options: SAMEORIGIN
x-permitted-cross-domain-policies: none
x-xss-protection: 0
REQUEST HEADERS
:authority: paizo.com
:method: GET
:path: /
:scheme: https
accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp ,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
accept-encoding: gzip, deflate, br
accept-language: es
cache-control: max-age=0
cookie: wosid=xxxxxxxxxxxxxxxxx; _pk_id.1.638a=xxxxxxxxxxxxxxxxxxxxxxxxx; _pk_ses.1.638a=1
sec-fetch-dest: document
sec-fetch-mode: navigate
sec-fetch-site: same-origin
sec-fetch-user: ?1
upgrade-insecure-requests: 1
user-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.83 Safari/537.36
Interestingly "curl https://paizo.com" works just fine.