Heroku
tcp/443 tcp/80
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3b571938e6585c57e05cd218cc362cfe870e6b3f2
GraphQL introspection enabled at /graphql Types: 110 (by kind: ENUM: 3, INPUT_OBJECT: 21, OBJECT: 76, SCALAR: 9, UNION: 1) Operations: - Query: Query | fields: authors, authors_aggregated, authors_by_id, blocks_templates, blocks_templates_by_id - Mutation: Mutation | fields: create_quiz_vizits_item, create_quiz_vizits_items, update_quiz_vizits_batch, update_quiz_vizits_item, update_quiz_vizits_items - Subscription: Subscription | fields: authors_mutated, blocks_templates_mutated, companies_companies_tags_mutated, companies_mutated, directus_files_mutated Directives: deprecated, include, skip (total: 3) Readable stores: 0
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3b571938e6585c57e05cd218cc362cfe870e6b3f2
GraphQL introspection enabled at /graphql Types: 110 (by kind: ENUM: 3, INPUT_OBJECT: 21, OBJECT: 76, SCALAR: 9, UNION: 1) Operations: - Query: Query | fields: authors, authors_aggregated, authors_by_id, blocks_templates, blocks_templates_by_id - Mutation: Mutation | fields: create_quiz_vizits_item, create_quiz_vizits_items, update_quiz_vizits_batch, update_quiz_vizits_item, update_quiz_vizits_items - Subscription: Subscription | fields: authors_mutated, blocks_templates_mutated, companies_companies_tags_mutated, companies_mutated, directus_files_mutated Directives: deprecated, include, skip (total: 3) Readable stores: 0
Open service 13.248.132.87:80 · api-mtx-prod.bairesdevai.com
2026-01-09 23:20
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://www.motrixsolutions.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Fri, 09 Jan 2026 23:21:23 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=mfBf7nU5NjqJ8W7%2BbcOGNqtpHQrCKgpoME7Bzy0Ptok%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1768000883"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=mfBf7nU5NjqJ8W7%2BbcOGNqtpHQrCKgpoME7Bzy0Ptok%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1768000883"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 75.2.97.79:443 · api-mtx-prod.bairesdevai.com
2026-01-09 08:19
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://www.motrixsolutions.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Fri, 09 Jan 2026 08:19:53 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=JGRIc2WtGaY0h1MkkzwLqUtDv1jx6Azw5tzN9fQurXM%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1767946793"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=JGRIc2WtGaY0h1MkkzwLqUtDv1jx6Azw5tzN9fQurXM%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1767946793"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 75.2.97.79:443 · api-mtx-prod.bairesdevai.com
2026-01-02 11:56
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://www.motrixsolutions.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Fri, 02 Jan 2026 11:56:26 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=9fbMhP3qppwUpmPVb8%2Fj%2BOGXRGIevz0vQsIRasDBTPs%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1767354986"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=9fbMhP3qppwUpmPVb8%2Fj%2BOGXRGIevz0vQsIRasDBTPs%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1767354986"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 13.248.132.87:80 · api-mtx-prod.bairesdevai.com
2025-12-30 10:47
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://www.motrixsolutions.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Tue, 30 Dec 2025 10:47:45 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=xrvmouKsEHSt9Vrx4EFY5kiWhSz51YGDXRXbWJbo%2BmA%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1767091665"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=xrvmouKsEHSt9Vrx4EFY5kiWhSz51YGDXRXbWJbo%2BmA%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1767091665"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 13.248.132.87:80 · api-mtx-prod.bairesdevai.com
2025-12-23 09:28
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://www.motrixsolutions.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Tue, 23 Dec 2025 09:28:39 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=BBqg%2Fg5t9YY%2FMlk2LRMMoBXcC1ufo7DPI5VBWjsnyhA%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766482119"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=BBqg%2Fg5t9YY%2FMlk2LRMMoBXcC1ufo7DPI5VBWjsnyhA%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766482119"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 75.2.97.79:443 · api-mtx-prod.bairesdevai.com
2025-12-22 20:00
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://www.motrixsolutions.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Mon, 22 Dec 2025 20:00:43 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=0ITFwaCJld5ICr9GAMnudBLxAtPGdMxqB6F0A1G3qm0%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766433643"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=0ITFwaCJld5ICr9GAMnudBLxAtPGdMxqB6F0A1G3qm0%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766433643"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 13.248.132.87:80 · api-mtx-prod.bairesdevai.com
2025-12-21 11:36
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://www.motrixsolutions.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Sun, 21 Dec 2025 11:36:41 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=WY8d28EbzRhgb7ZXbWQXZAn5WgOjf%2BV%2FdKi%2FCMrt1nQ%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766317001"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=WY8d28EbzRhgb7ZXbWQXZAn5WgOjf%2BV%2FdKi%2FCMrt1nQ%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766317001"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 75.2.97.79:443 · api-mtx-prod.bairesdevai.com
2025-12-21 04:20
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://www.motrixsolutions.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Sun, 21 Dec 2025 04:20:32 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=8PYPuBgcB1y2i6Vcgsq3bUm447C3Td3dl5gl5MDk1cY%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766290832"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=8PYPuBgcB1y2i6Vcgsq3bUm447C3Td3dl5gl5MDk1cY%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766290832"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 13.248.132.87:80 · api-mtx-prod.bairesdevai.com
2025-12-19 09:34
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://www.motrixsolutions.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Fri, 19 Dec 2025 09:34:24 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=UdPi62CGejx59ID%2B9p4HcWDIHTDyyFIDy0xMsEiHVV4%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766136864"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=UdPi62CGejx59ID%2B9p4HcWDIHTDyyFIDy0xMsEiHVV4%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766136864"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 75.2.97.79:443 · api-mtx-prod.bairesdevai.com
2025-12-19 04:28
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://www.motrixsolutions.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Fri, 19 Dec 2025 04:28:39 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=KxKu50%2BkW23z40uOk167tb6GtWOPipeLepoCqjn8f5o%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766118519"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=KxKu50%2BkW23z40uOk167tb6GtWOPipeLepoCqjn8f5o%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766118519"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin