Heroku
tcp/443 tcp/80
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3b01c8f669f2235167c1ada53a56c4489a58a2d3d
GraphQL introspection enabled at /graphql Types: 124 (by kind: ENUM: 3, INPUT_OBJECT: 22, OBJECT: 89, SCALAR: 9, UNION: 1) Operations: - Query: Query | fields: authors, authors_aggregated, authors_by_id, authors_by_version, blocks_templates - Mutation: Mutation | fields: create_quiz_vizits_item, create_quiz_vizits_items, update_quiz_vizits_batch, update_quiz_vizits_item, update_quiz_vizits_items - Subscription: Subscription | fields: authors_mutated, blocks_templates_mutated, companies_companies_tags_mutated, companies_mutated, companies_tags_mutated Directives: deprecated, include, skip (total: 3) Readable stores: 0
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3b01c8f669f2235167c1ada53a56c4489a58a2d3d
GraphQL introspection enabled at /graphql Types: 124 (by kind: ENUM: 3, INPUT_OBJECT: 22, OBJECT: 89, SCALAR: 9, UNION: 1) Operations: - Query: Query | fields: authors, authors_aggregated, authors_by_id, authors_by_version, blocks_templates - Mutation: Mutation | fields: create_quiz_vizits_item, create_quiz_vizits_items, update_quiz_vizits_batch, update_quiz_vizits_item, update_quiz_vizits_items - Subscription: Subscription | fields: authors_mutated, blocks_templates_mutated, companies_companies_tags_mutated, companies_mutated, companies_tags_mutated Directives: deprecated, include, skip (total: 3) Readable stores: 0
Open service 15.197.149.68:80 · api-dev.devoutsourcing.com
2026-01-09 09:09
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://dev.devoutsourcing.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://raw.githubusercontent.com https://avatars.githubusercontent.com;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Fri, 09 Jan 2026 09:10:07 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=h5myVL9N%2Fw8ul3OoiygpDCNWtMCedhrFJvcz3khbJ1c%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767949807"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=h5myVL9N%2Fw8ul3OoiygpDCNWtMCedhrFJvcz3khbJ1c%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767949807"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 3.33.241.96:443 · api-dev.devoutsourcing.com
2026-01-08 22:15
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://dev.devoutsourcing.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://raw.githubusercontent.com https://avatars.githubusercontent.com;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Thu, 08 Jan 2026 22:15:04 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=sS34wKfOHue8HxHED%2Fv7am9i0K76pQiiHnoaCLMfyBM%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767910504"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=sS34wKfOHue8HxHED%2Fv7am9i0K76pQiiHnoaCLMfyBM%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767910504"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 3.33.241.96:443 · api-dev.devoutsourcing.com
2026-01-02 11:42
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://dev.devoutsourcing.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://raw.githubusercontent.com https://avatars.githubusercontent.com;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Fri, 02 Jan 2026 11:42:11 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=FgR0WmEzFHoanEen3KOaaWRlJaxOAl%2BaoUVhiVN%2BbkE%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767354131"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=FgR0WmEzFHoanEen3KOaaWRlJaxOAl%2BaoUVhiVN%2BbkE%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767354131"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 15.197.149.68:80 · api-dev.devoutsourcing.com
2026-01-01 19:35
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://dev.devoutsourcing.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://raw.githubusercontent.com https://avatars.githubusercontent.com;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Thu, 01 Jan 2026 19:35:06 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=kTqtlSy42IYRcNXQrX6RKTf485VFQNWFR8VnF55FBlI%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767296106"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=kTqtlSy42IYRcNXQrX6RKTf485VFQNWFR8VnF55FBlI%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767296106"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 15.197.149.68:80 · api-dev.devoutsourcing.com
2025-12-22 22:17
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://dev.devoutsourcing.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://raw.githubusercontent.com https://avatars.githubusercontent.com;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Mon, 22 Dec 2025 22:17:29 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=f3CEOQNixKE19poSIHJnVxEyb1B9TxpCHPIZLRa5Gx0%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766441849"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=f3CEOQNixKE19poSIHJnVxEyb1B9TxpCHPIZLRa5Gx0%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766441849"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 3.33.241.96:443 · api-dev.devoutsourcing.com
2025-12-22 20:44
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://dev.devoutsourcing.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://raw.githubusercontent.com https://avatars.githubusercontent.com;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Mon, 22 Dec 2025 20:44:43 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=bW37wuZO1CLVCbbkhTfKsxrWbVpqHAaWjFd65hO%2BRZc%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766436283"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=bW37wuZO1CLVCbbkhTfKsxrWbVpqHAaWjFd65hO%2BRZc%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766436283"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 15.197.149.68:80 · api-dev.devoutsourcing.com
2025-12-21 09:18
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://dev.devoutsourcing.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://raw.githubusercontent.com https://avatars.githubusercontent.com;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Sun, 21 Dec 2025 09:18:03 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=yMm3tMBV%2BHj%2B7IHbeaNtdJvGyIDa%2FU3yMOHG1LPcCOE%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766308683"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=yMm3tMBV%2BHj%2B7IHbeaNtdJvGyIDa%2FU3yMOHG1LPcCOE%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766308683"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 3.33.241.96:443 · api-dev.devoutsourcing.com
2025-12-21 00:52
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://dev.devoutsourcing.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://raw.githubusercontent.com https://avatars.githubusercontent.com;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Sun, 21 Dec 2025 00:52:08 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=Svvk8dFpgPNqRbFzPQUfLfvoULfsXbTzsGh7ttcpBPo%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766278328"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=Svvk8dFpgPNqRbFzPQUfLfvoULfsXbTzsGh7ttcpBPo%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766278328"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 15.197.149.68:80 · api-dev.devoutsourcing.com
2025-12-19 11:06
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://dev.devoutsourcing.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://raw.githubusercontent.com https://avatars.githubusercontent.com;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Fri, 19 Dec 2025 11:07:00 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=YInMVkgCGbJukujWvxUkedYIocFpLd6bFfrr8xJO6us%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766142420"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=YInMVkgCGbJukujWvxUkedYIocFpLd6bFfrr8xJO6us%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766142420"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin