GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3a97050fa57cf2eaa490a7fad6a373363cdb670e7
GraphQL introspection enabled at /graphql Types: 50 (by kind: ENUM: 3, INPUT_OBJECT: 8, OBJECT: 30, SCALAR: 9) Operations: - Query: Query | fields: groups, pages, pages_aggregated, pages_by_id, pages_by_version - Subscription: Subscription | fields: articles_mutated, directus_files_mutated, groups_mutated, pages_mutated Directives: deprecated, include, skip (total: 3) Readable stores: 0
Open service 2.18.64.7:443 · api.documentation.molink.fr
2026-01-23 06:36
HTTP/1.1 302 Moved Temporarily Content-Type: text/plain; charset=utf-8 Content-Length: 29 Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://raw.githubusercontent.com https://avatars.githubusercontent.com;media-src 'self';connect-src 'self' https://* wss://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline' Vary: Origin, Accept Access-Control-Allow-Credentials: true Access-Control-Expose-Headers: Content-Range Location: ./admin Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Fri, 23 Jan 2026 06:36:30 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 23 Jan 2026 06:36:30 GMT Connection: close Found. Redirecting to ./admin
Open service 2.18.64.7:443 · api.documentation.molink.fr
2026-01-09 07:19
HTTP/1.1 302 Moved Temporarily Content-Type: text/plain; charset=utf-8 Content-Length: 29 Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://raw.githubusercontent.com https://avatars.githubusercontent.com;media-src 'self';connect-src 'self' https://* wss://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline' Vary: Origin, Accept Access-Control-Allow-Credentials: true Access-Control-Expose-Headers: Content-Range Location: ./admin Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Fri, 09 Jan 2026 07:19:37 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 09 Jan 2026 07:19:37 GMT Connection: close Found. Redirecting to ./admin
Open service 2.18.64.7:443 · api.documentation.molink.fr
2026-01-02 14:31
HTTP/1.1 302 Moved Temporarily Content-Type: text/plain; charset=utf-8 Content-Length: 29 Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://raw.githubusercontent.com https://avatars.githubusercontent.com;media-src 'self';connect-src 'self' https://* wss://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline' Vary: Origin, Accept Access-Control-Allow-Credentials: true Access-Control-Expose-Headers: Content-Range Location: ./admin Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Fri, 02 Jan 2026 14:31:09 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 02 Jan 2026 14:31:09 GMT Connection: close Found. Redirecting to ./admin
Open service 2.18.64.7:443 · api.documentation.molink.fr
2025-12-23 02:33
HTTP/1.1 302 Moved Temporarily Content-Type: text/plain; charset=utf-8 Content-Length: 29 Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://raw.githubusercontent.com https://avatars.githubusercontent.com;media-src 'self';connect-src 'self' https://* wss://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline' Vary: Origin, Accept Access-Control-Allow-Credentials: true Access-Control-Expose-Headers: Content-Range Location: ./admin Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Tue, 23 Dec 2025 02:33:36 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 23 Dec 2025 02:33:36 GMT Connection: close Found. Redirecting to ./admin