Heroku
tcp/443 tcp/80
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3d8cee82a540f0a1ae3344268ad23cae4ac765ddc
GraphQL introspection enabled at /graphql Types: 94 (by kind: ENUM: 2, INPUT_OBJECT: 21, OBJECT: 61, SCALAR: 9, UNION: 1) Operations: - Query: Query | fields: authors, authors_aggregated, authors_by_id, blocks_templates, blocks_templates_by_id - Mutation: Mutation | fields: create_quiz_vizits_item, create_quiz_vizits_items, update_quiz_vizits_batch, update_quiz_vizits_item, update_quiz_vizits_items Directives: deprecated, include, skip (total: 3) Readable stores: 0
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3d8cee82a540f0a1ae3344268ad23cae4ac765ddc
GraphQL introspection enabled at /graphql Types: 94 (by kind: ENUM: 2, INPUT_OBJECT: 21, OBJECT: 61, SCALAR: 9, UNION: 1) Operations: - Query: Query | fields: authors, authors_aggregated, authors_by_id, blocks_templates, blocks_templates_by_id - Mutation: Mutation | fields: create_quiz_vizits_item, create_quiz_vizits_items, update_quiz_vizits_batch, update_quiz_vizits_item, update_quiz_vizits_items Directives: deprecated, include, skip (total: 3) Readable stores: 0
Open service 99.83.220.108:80 · api-editor.devoutsourcing.com
2026-01-09 17:23
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://editor.devoutsourcing.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Fri, 09 Jan 2026 17:24:46 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=eWoxVfQdUEmCQXpmWYHo5r8y5Y%2B4M2bA%2F%2FmuCPg3Hv8%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767979486"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=eWoxVfQdUEmCQXpmWYHo5r8y5Y%2B4M2bA%2F%2FmuCPg3Hv8%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767979486"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 75.2.60.68:443 · api-editor.devoutsourcing.com
2026-01-09 17:23
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://editor.devoutsourcing.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Fri, 09 Jan 2026 17:23:46 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=KSBUryse15zB%2FtmkPZgRM3Tx7lZUx6aHcmxp4jTZ13Q%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767979426"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=KSBUryse15zB%2FtmkPZgRM3Tx7lZUx6aHcmxp4jTZ13Q%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767979426"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 75.2.60.68:443 · api-editor.devoutsourcing.com
2026-01-02 23:16
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://editor.devoutsourcing.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Fri, 02 Jan 2026 23:16:57 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=%2FIK614kVNXcvp7roQvqXnpB0vFlUOm7OHfyoeFewqwU%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767395817"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=%2FIK614kVNXcvp7roQvqXnpB0vFlUOm7OHfyoeFewqwU%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767395817"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 99.83.220.108:80 · api-editor.devoutsourcing.com
2026-01-02 23:16
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://editor.devoutsourcing.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Fri, 02 Jan 2026 23:17:00 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=jkztfKQ5y%2FJLnWw%2F5sbCi5ULfFvBh0Gjt2AwE8vx%2FuA%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767395820"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=jkztfKQ5y%2FJLnWw%2F5sbCi5ULfFvBh0Gjt2AwE8vx%2FuA%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767395820"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 99.83.220.108:80 · api-editor.devoutsourcing.com
2025-12-30 09:56
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://editor.devoutsourcing.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Tue, 30 Dec 2025 09:56:13 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=1ZCbTXszArSY6x0AuqzJatB6H1NrGsB%2Fq76KJSkkeWg%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767088573"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=1ZCbTXszArSY6x0AuqzJatB6H1NrGsB%2Fq76KJSkkeWg%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767088573"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 75.2.60.68:443 · api-editor.devoutsourcing.com
2025-12-30 09:56
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://editor.devoutsourcing.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Tue, 30 Dec 2025 09:56:09 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=O4LvWIU0PSsUv2qRdM81hoa6RKKnliw%2BRIdqF1sxZIs%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767088569"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=O4LvWIU0PSsUv2qRdM81hoa6RKKnliw%2BRIdqF1sxZIs%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767088569"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 75.2.60.68:443 · api-editor.devoutsourcing.com
2025-12-22 22:44
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://editor.devoutsourcing.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Mon, 22 Dec 2025 22:44:23 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=2Wd17fXbwCfFrFp10Ntl7bnysly2C40uzfT38SNzul0%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766443463"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=2Wd17fXbwCfFrFp10Ntl7bnysly2C40uzfT38SNzul0%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766443463"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 99.83.220.108:80 · api-editor.devoutsourcing.com
2025-12-22 22:44
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://editor.devoutsourcing.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Mon, 22 Dec 2025 22:44:26 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=NPNtF63TSTyjI7NydjZnbddqAkKQUMTqKbkv8rAiXkM%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766443466"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=NPNtF63TSTyjI7NydjZnbddqAkKQUMTqKbkv8rAiXkM%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766443466"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 75.2.60.68:443 · api-editor.devoutsourcing.com
2025-12-21 03:00
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://editor.devoutsourcing.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Sun, 21 Dec 2025 03:00:50 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=F7jQ2%2BARVLN5Bna3ulvCU5Uz6ShlFPFtkCHdjCRvGzw%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766286050"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=F7jQ2%2BARVLN5Bna3ulvCU5Uz6ShlFPFtkCHdjCRvGzw%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766286050"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 99.83.220.108:80 · api-editor.devoutsourcing.com
2025-12-21 03:00
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://editor.devoutsourcing.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Sun, 21 Dec 2025 03:00:52 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=6ftyxjAKLeRCM7sTxdpUTPYmLf5W85PQgf38HbNuueE%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766286052"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=6ftyxjAKLeRCM7sTxdpUTPYmLf5W85PQgf38HbNuueE%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766286052"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 75.2.60.68:443 · api-editor.devoutsourcing.com
2025-12-19 03:19
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://editor.devoutsourcing.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Fri, 19 Dec 2025 03:19:29 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=q5hstxy2%2BOM1CpPlR%2BX%2FLyvmWGnIEmXr8YuD3ThSEIw%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766114369"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=q5hstxy2%2BOM1CpPlR%2BX%2FLyvmWGnIEmXr8YuD3ThSEIw%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766114369"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 99.83.220.108:80 · api-editor.devoutsourcing.com
2025-12-19 03:19
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://editor.devoutsourcing.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Fri, 19 Dec 2025 03:19:31 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=pQ94WQdAxCUSOyrPJXU4Z7KSnASlnRJezKP2YJ2gwFI%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766114371"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=pQ94WQdAxCUSOyrPJXU4Z7KSnASlnRJezKP2YJ2gwFI%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766114371"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin