Heroku
tcp/443 tcp/80
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd151e75e4bc2656850b401c04af7bb586a5a515f3dfad9413d
Public Swagger UI/API detected at path: /v3/api-docs - sample paths:
DELETE /api/leagues/{leagueId}/exit/players/{playerId}
DELETE /api/points/{id}
GET /api/achievements/bonus
GET /api/achievements/malus
GET /api/characters
GET /api/characters/leaderboards
GET /api/contents
GET /api/forms
GET /api/forms/active
GET /api/forms/leaderboards
GET /api/forms/players/{playerId}
GET /api/forms/{id}/answers
GET /api/goals/players/{playerId}
GET /api/leagues
GET /api/leagues/players/{playerId}
GET /api/leagues/{leagueId}
GET /api/leagues/{leagueId}/leaderboards
GET /api/leagues/{leagueId}/partecipants
GET /api/leagues/{leagueId}/players/{playerId}
GET /api/login/build
GET /api/players/count
GET /api/players/count/today
GET /api/players/{playerId}
GET /api/points
GET /api/rewards/players/{playerId}
GET /api/rules
GET /api/seasons/current/episode
GET /api/seasons/next/episode
GET /api/shops
GET /api/shops/players/{playerId}/purchases
GET /api/teams/{id}
PATCH /api/players/{playerId}/img
POST /api/contents/news
POST /api/contents/sponsor
POST /api/forms/{id}/active
POST /api/forms/{id}/inactive
POST /api/leagues/{leagueId}/active
POST /api/leagues/{leagueId}/inactive
POST /api/login
POST /api/login/admin
POST /api/login/tokens
POST /api/notifications
POST /api/notifications/tokens
POST /api/notifications/{playerId}
POST /api/players
POST /api/players/{playerId}/logout
POST /api/shops/purchase
POST /api/shops/redeem/{playerId}/{shopItemId}
POST /api/teams
PUT /api/contents/news/{id}
PUT /api/contents/sponsor/{id}
PUT /api/forms/{id}
PUT /api/goals/collect/{goalId}/players/{playerId}
PUT /api/goals/daily/players/{playerId}
Severity: info
Fingerprint: 5733ddf49ff49cd151e75e4bc2656850b401c04af7bb586a5a515f3df651b8a2
Public Swagger UI/API detected at path: /v3/api-docs - sample paths:
DELETE /api/leagues/{leagueId}/exit/players/{playerId}
DELETE /api/points/{id}
GET /api/achievements/bonus
GET /api/achievements/malus
GET /api/characters
GET /api/characters/leaderboards
GET /api/contents
GET /api/forms
GET /api/forms/active
GET /api/forms/leaderboards
GET /api/forms/players/{playerId}
GET /api/forms/{id}/answers
GET /api/goals/players/{playerId}
GET /api/leagues
GET /api/leagues/players/{playerId}
GET /api/leagues/{leagueId}
GET /api/leagues/{leagueId}/leaderboards
GET /api/leagues/{leagueId}/partecipants
GET /api/leagues/{leagueId}/players/{playerId}
GET /api/login/build
GET /api/players/count
GET /api/players/count/today
GET /api/players/{playerId}
GET /api/points
GET /api/rewards/players/{playerId}
GET /api/rules
GET /api/seasons/current/episode
GET /api/seasons/next/episode
GET /api/shops
GET /api/shops/players/{playerId}/purchases
GET /api/teams/{id}
PATCH /api/players/{playerId}/img
POST /api/contents/news
POST /api/contents/sponsor
POST /api/forms/{id}/active
POST /api/forms/{id}/inactive
POST /api/leagues/{leagueId}/active
POST /api/leagues/{leagueId}/inactive
POST /api/login
POST /api/login/admin
POST /api/login/tokens
POST /api/notifications
POST /api/notifications/tokens
POST /api/notifications/{playerId}
POST /api/players
POST /api/players/{playerId}/logout
POST /api/shops/purchase
POST /api/shops/redeem/{playerId}/{shopItemId}
POST /api/teams
PUT /api/contents/news/{id}
PUT /api/contents/sponsor/{id}
PUT /api/forms/{id}
PUT /api/goals/collect/{goalId}/players/{playerId}
Severity: info
Fingerprint: 5733ddf49ff49cd151e75e4bc2656850b401c04af7bb586a5a515f3d9f360cf6
Public Swagger UI/API detected at path: /v3/api-docs - sample paths:
DELETE /api/leagues/{leagueId}/exit/players/{playerId}
DELETE /api/points/{id}
GET /api/achievements/bonus
GET /api/achievements/malus
GET /api/characters
GET /api/characters/leaderboards
GET /api/contents
GET /api/forms
GET /api/forms/active
GET /api/forms/leaderboards
GET /api/forms/players/{playerId}
GET /api/forms/{id}/answers
GET /api/goals/players/{playerId}
GET /api/leagues
GET /api/leagues/players/{playerId}
GET /api/leagues/{leagueId}
GET /api/leagues/{leagueId}/leaderboards
GET /api/leagues/{leagueId}/partecipants
GET /api/leagues/{leagueId}/players/{playerId}
GET /api/login/build
GET /api/players/count
GET /api/players/count/today
GET /api/players/{playerId}
GET /api/points
GET /api/rewards/players/{playerId}
GET /api/rules
GET /api/seasons/current/episode
GET /api/seasons/next/episode
GET /api/shops
GET /api/shops/players/{playerId}/purchases
GET /api/teams/{id}
PATCH /api/players/{playerId}/img
POST /api/contents/news
POST /api/contents/sponsor
POST /api/forms/{id}/active
POST /api/forms/{id}/inactive
POST /api/leagues/{leagueId}/active
POST /api/leagues/{leagueId}/inactive
POST /api/login
POST /api/login/admin
POST /api/login/tokens
POST /api/notifications
POST /api/notifications/tokens
POST /api/notifications/{playerId}
POST /api/players
POST /api/players/{playerId}/logout
POST /api/shops/purchase/{playerId}/{shopItemId}
POST /api/teams
PUT /api/contents/news/{id}
PUT /api/contents/sponsor/{id}
PUT /api/forms/{id}
PUT /api/goals/collect/{goalId}/players/{playerId}
Severity: info
Fingerprint: 5733ddf49ff49cd151e75e4bc2656850b401c04af7bb586a5a515f3de295a10a
Public Swagger UI/API detected at path: /v3/api-docs - sample paths:
DELETE /api/leagues/{leagueId}/exit/players/{playerId}
DELETE /api/points/{id}
GET /api/achievements/bonus
GET /api/achievements/malus
GET /api/characters
GET /api/characters/leaderboards
GET /api/contents
GET /api/forms
GET /api/forms/active
GET /api/forms/leaderboards
GET /api/forms/players/{playerId}
GET /api/forms/{id}/answers
GET /api/goals/players/{playerId}
GET /api/leagues
GET /api/leagues/players/{playerId}
GET /api/leagues/{leagueId}
GET /api/leagues/{leagueId}/leaderboards
GET /api/leagues/{leagueId}/partecipants
GET /api/leagues/{leagueId}/players/{playerId}
GET /api/login/build
GET /api/players/count
GET /api/players/count/today
GET /api/players/{playerId}
GET /api/points
GET /api/rewards/players/{playerId}
GET /api/rules
GET /api/seasons/current/episode
GET /api/seasons/next/episode
GET /api/shops
GET /api/shops/players/{playerId}/purchases
GET /api/teams/{id}
PATCH /api/players/{playerId}/img
POST /api/forms/{id}/active
POST /api/forms/{id}/inactive
POST /api/leagues/{leagueId}/active
POST /api/leagues/{leagueId}/inactive
POST /api/login
POST /api/login/admin
POST /api/login/tokens
POST /api/notifications
POST /api/notifications/tokens
POST /api/notifications/{playerId}
POST /api/players
POST /api/players/{playerId}/logout
POST /api/shops/purchase/{playerId}/{shopItemId}
POST /api/teams
PUT /api/forms/{id}
PUT /api/goals/collect/{goalId}/players/{playerId}
Severity: info
Fingerprint: 5733ddf49ff49cd151e75e4bc2656850b401c04af7bb586a5a515f3d2ffc59c5
Public Swagger UI/API detected at path: /v3/api-docs - sample paths:
DELETE /api/leagues/{leagueId}/exit/players/{playerId}
DELETE /api/points/{id}
GET /api/achievements/bonus
GET /api/achievements/malus
GET /api/characters
GET /api/characters/leaderboards
GET /api/contents
GET /api/forms
GET /api/forms/active
GET /api/forms/leaderboards
GET /api/forms/players/{playerId}
GET /api/forms/{id}/answers
GET /api/goals/players/{playerId}
GET /api/leagues
GET /api/leagues/players/{playerId}
GET /api/leagues/{leagueId}
GET /api/leagues/{leagueId}/leaderboards
GET /api/leagues/{leagueId}/partecipants
GET /api/leagues/{leagueId}/players/{playerId}
GET /api/login/build
GET /api/players/count
GET /api/players/count/today
GET /api/players/{playerId}
GET /api/points
GET /api/rewards/players/{playerId}
GET /api/rules
GET /api/seasons/current/episode
GET /api/seasons/next/episode
GET /api/shops
GET /api/shops/players/{playerId}/purchases
GET /api/teams/{id}
PATCH /api/players/{playerId}/img
POST /api/forms/{id}/active
POST /api/forms/{id}/inactive
POST /api/leagues/{leagueId}/active
POST /api/leagues/{leagueId}/inactive
POST /api/login
POST /api/login/admin
POST /api/login/tokens
POST /api/notifications
POST /api/notifications/tokens
POST /api/notifications/{playerId}
POST /api/players
POST /api/players/{playerId}/logout
POST /api/shops/purchase/{playerId}/{shopItemId}
POST /api/teams
PUT /api/forms/{id}
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd151e75e4bc2656850b401c04af7bb586a5a515f3dfad9413d
Public Swagger UI/API detected at path: /v3/api-docs - sample paths:
DELETE /api/leagues/{leagueId}/exit/players/{playerId}
DELETE /api/points/{id}
GET /api/achievements/bonus
GET /api/achievements/malus
GET /api/characters
GET /api/characters/leaderboards
GET /api/contents
GET /api/forms
GET /api/forms/active
GET /api/forms/leaderboards
GET /api/forms/players/{playerId}
GET /api/forms/{id}/answers
GET /api/goals/players/{playerId}
GET /api/leagues
GET /api/leagues/players/{playerId}
GET /api/leagues/{leagueId}
GET /api/leagues/{leagueId}/leaderboards
GET /api/leagues/{leagueId}/partecipants
GET /api/leagues/{leagueId}/players/{playerId}
GET /api/login/build
GET /api/players/count
GET /api/players/count/today
GET /api/players/{playerId}
GET /api/points
GET /api/rewards/players/{playerId}
GET /api/rules
GET /api/seasons/current/episode
GET /api/seasons/next/episode
GET /api/shops
GET /api/shops/players/{playerId}/purchases
GET /api/teams/{id}
PATCH /api/players/{playerId}/img
POST /api/contents/news
POST /api/contents/sponsor
POST /api/forms/{id}/active
POST /api/forms/{id}/inactive
POST /api/leagues/{leagueId}/active
POST /api/leagues/{leagueId}/inactive
POST /api/login
POST /api/login/admin
POST /api/login/tokens
POST /api/notifications
POST /api/notifications/tokens
POST /api/notifications/{playerId}
POST /api/players
POST /api/players/{playerId}/logout
POST /api/shops/purchase
POST /api/shops/redeem/{playerId}/{shopItemId}
POST /api/teams
PUT /api/contents/news/{id}
PUT /api/contents/sponsor/{id}
PUT /api/forms/{id}
PUT /api/goals/collect/{goalId}/players/{playerId}
PUT /api/goals/daily/players/{playerId}
Severity: info
Fingerprint: 5733ddf49ff49cd151e75e4bc2656850b401c04af7bb586a5a515f3df651b8a2
Public Swagger UI/API detected at path: /v3/api-docs - sample paths:
DELETE /api/leagues/{leagueId}/exit/players/{playerId}
DELETE /api/points/{id}
GET /api/achievements/bonus
GET /api/achievements/malus
GET /api/characters
GET /api/characters/leaderboards
GET /api/contents
GET /api/forms
GET /api/forms/active
GET /api/forms/leaderboards
GET /api/forms/players/{playerId}
GET /api/forms/{id}/answers
GET /api/goals/players/{playerId}
GET /api/leagues
GET /api/leagues/players/{playerId}
GET /api/leagues/{leagueId}
GET /api/leagues/{leagueId}/leaderboards
GET /api/leagues/{leagueId}/partecipants
GET /api/leagues/{leagueId}/players/{playerId}
GET /api/login/build
GET /api/players/count
GET /api/players/count/today
GET /api/players/{playerId}
GET /api/points
GET /api/rewards/players/{playerId}
GET /api/rules
GET /api/seasons/current/episode
GET /api/seasons/next/episode
GET /api/shops
GET /api/shops/players/{playerId}/purchases
GET /api/teams/{id}
PATCH /api/players/{playerId}/img
POST /api/contents/news
POST /api/contents/sponsor
POST /api/forms/{id}/active
POST /api/forms/{id}/inactive
POST /api/leagues/{leagueId}/active
POST /api/leagues/{leagueId}/inactive
POST /api/login
POST /api/login/admin
POST /api/login/tokens
POST /api/notifications
POST /api/notifications/tokens
POST /api/notifications/{playerId}
POST /api/players
POST /api/players/{playerId}/logout
POST /api/shops/purchase
POST /api/shops/redeem/{playerId}/{shopItemId}
POST /api/teams
PUT /api/contents/news/{id}
PUT /api/contents/sponsor/{id}
PUT /api/forms/{id}
PUT /api/goals/collect/{goalId}/players/{playerId}
Severity: info
Fingerprint: 5733ddf49ff49cd151e75e4bc2656850b401c04af7bb586a5a515f3d9f360cf6
Public Swagger UI/API detected at path: /v3/api-docs - sample paths:
DELETE /api/leagues/{leagueId}/exit/players/{playerId}
DELETE /api/points/{id}
GET /api/achievements/bonus
GET /api/achievements/malus
GET /api/characters
GET /api/characters/leaderboards
GET /api/contents
GET /api/forms
GET /api/forms/active
GET /api/forms/leaderboards
GET /api/forms/players/{playerId}
GET /api/forms/{id}/answers
GET /api/goals/players/{playerId}
GET /api/leagues
GET /api/leagues/players/{playerId}
GET /api/leagues/{leagueId}
GET /api/leagues/{leagueId}/leaderboards
GET /api/leagues/{leagueId}/partecipants
GET /api/leagues/{leagueId}/players/{playerId}
GET /api/login/build
GET /api/players/count
GET /api/players/count/today
GET /api/players/{playerId}
GET /api/points
GET /api/rewards/players/{playerId}
GET /api/rules
GET /api/seasons/current/episode
GET /api/seasons/next/episode
GET /api/shops
GET /api/shops/players/{playerId}/purchases
GET /api/teams/{id}
PATCH /api/players/{playerId}/img
POST /api/contents/news
POST /api/contents/sponsor
POST /api/forms/{id}/active
POST /api/forms/{id}/inactive
POST /api/leagues/{leagueId}/active
POST /api/leagues/{leagueId}/inactive
POST /api/login
POST /api/login/admin
POST /api/login/tokens
POST /api/notifications
POST /api/notifications/tokens
POST /api/notifications/{playerId}
POST /api/players
POST /api/players/{playerId}/logout
POST /api/shops/purchase/{playerId}/{shopItemId}
POST /api/teams
PUT /api/contents/news/{id}
PUT /api/contents/sponsor/{id}
PUT /api/forms/{id}
PUT /api/goals/collect/{goalId}/players/{playerId}
Severity: info
Fingerprint: 5733ddf49ff49cd151e75e4bc2656850b401c04af7bb586a5a515f3de295a10a
Public Swagger UI/API detected at path: /v3/api-docs - sample paths:
DELETE /api/leagues/{leagueId}/exit/players/{playerId}
DELETE /api/points/{id}
GET /api/achievements/bonus
GET /api/achievements/malus
GET /api/characters
GET /api/characters/leaderboards
GET /api/contents
GET /api/forms
GET /api/forms/active
GET /api/forms/leaderboards
GET /api/forms/players/{playerId}
GET /api/forms/{id}/answers
GET /api/goals/players/{playerId}
GET /api/leagues
GET /api/leagues/players/{playerId}
GET /api/leagues/{leagueId}
GET /api/leagues/{leagueId}/leaderboards
GET /api/leagues/{leagueId}/partecipants
GET /api/leagues/{leagueId}/players/{playerId}
GET /api/login/build
GET /api/players/count
GET /api/players/count/today
GET /api/players/{playerId}
GET /api/points
GET /api/rewards/players/{playerId}
GET /api/rules
GET /api/seasons/current/episode
GET /api/seasons/next/episode
GET /api/shops
GET /api/shops/players/{playerId}/purchases
GET /api/teams/{id}
PATCH /api/players/{playerId}/img
POST /api/forms/{id}/active
POST /api/forms/{id}/inactive
POST /api/leagues/{leagueId}/active
POST /api/leagues/{leagueId}/inactive
POST /api/login
POST /api/login/admin
POST /api/login/tokens
POST /api/notifications
POST /api/notifications/tokens
POST /api/notifications/{playerId}
POST /api/players
POST /api/players/{playerId}/logout
POST /api/shops/purchase/{playerId}/{shopItemId}
POST /api/teams
PUT /api/forms/{id}
PUT /api/goals/collect/{goalId}/players/{playerId}
Severity: info
Fingerprint: 5733ddf49ff49cd151e75e4bc2656850b401c04af7bb586a5a515f3d2ffc59c5
Public Swagger UI/API detected at path: /v3/api-docs - sample paths:
DELETE /api/leagues/{leagueId}/exit/players/{playerId}
DELETE /api/points/{id}
GET /api/achievements/bonus
GET /api/achievements/malus
GET /api/characters
GET /api/characters/leaderboards
GET /api/contents
GET /api/forms
GET /api/forms/active
GET /api/forms/leaderboards
GET /api/forms/players/{playerId}
GET /api/forms/{id}/answers
GET /api/goals/players/{playerId}
GET /api/leagues
GET /api/leagues/players/{playerId}
GET /api/leagues/{leagueId}
GET /api/leagues/{leagueId}/leaderboards
GET /api/leagues/{leagueId}/partecipants
GET /api/leagues/{leagueId}/players/{playerId}
GET /api/login/build
GET /api/players/count
GET /api/players/count/today
GET /api/players/{playerId}
GET /api/points
GET /api/rewards/players/{playerId}
GET /api/rules
GET /api/seasons/current/episode
GET /api/seasons/next/episode
GET /api/shops
GET /api/shops/players/{playerId}/purchases
GET /api/teams/{id}
PATCH /api/players/{playerId}/img
POST /api/forms/{id}/active
POST /api/forms/{id}/inactive
POST /api/leagues/{leagueId}/active
POST /api/leagues/{leagueId}/inactive
POST /api/login
POST /api/login/admin
POST /api/login/tokens
POST /api/notifications
POST /api/notifications/tokens
POST /api/notifications/{playerId}
POST /api/players
POST /api/players/{playerId}/logout
POST /api/shops/purchase/{playerId}/{shopItemId}
POST /api/teams
PUT /api/forms/{id}
Open service 15.197.129.158:80 · api.fantati.it
2026-01-10 02:43
HTTP/1.1 403 Forbidden
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Sat, 10 Jan 2026 02:44:16 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=0EN34ufSJDITt36l2UKtSfLo8NYOkT8wpfxZmc1QXrs%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1768013056"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=0EN34ufSJDITt36l2UKtSfLo8NYOkT8wpfxZmc1QXrs%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1768013056"
Server: Heroku
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 99.83.217.1:443 · api.fantati.it
2026-01-09 23:11
HTTP/1.1 403 Forbidden
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Fri, 09 Jan 2026 23:11:05 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=SVchM7qqHKOXpSv%2B5%2F1E0qgLZYIKt7O4aYhvz%2FJ8TaE%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1768000265"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=SVchM7qqHKOXpSv%2B5%2F1E0qgLZYIKt7O4aYhvz%2FJ8TaE%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1768000265"
Server: Heroku
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 75.2.43.161:80 · api.fantati.it
2026-01-07 00:43
HTTP/1.1 403 Forbidden
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Wed, 07 Jan 2026 00:44:45 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=GhIxlBSAH%2FhgZtUTtlyzk9Yd4jvGWF6O0qUYyrq9UE0%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767746685"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=GhIxlBSAH%2FhgZtUTtlyzk9Yd4jvGWF6O0qUYyrq9UE0%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767746685"
Server: Heroku
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 76.223.11.49:80 · api.fantati.it
2026-01-07 00:43
HTTP/1.1 403 Forbidden
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Wed, 07 Jan 2026 00:44:45 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=GhIxlBSAH%2FhgZtUTtlyzk9Yd4jvGWF6O0qUYyrq9UE0%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767746685"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=GhIxlBSAH%2FhgZtUTtlyzk9Yd4jvGWF6O0qUYyrq9UE0%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767746685"
Server: Heroku
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 75.2.43.161:443 · api.fantati.it
2026-01-07 00:43
HTTP/1.1 403 Forbidden
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Wed, 07 Jan 2026 00:43:44 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=%2BSq55VH59bofC5oA7TDZDgKfHXU86v9RH6qnmEF0xSQ%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767746624"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=%2BSq55VH59bofC5oA7TDZDgKfHXU86v9RH6qnmEF0xSQ%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767746624"
Server: Heroku
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 99.83.217.1:443 · api.fantati.it
2026-01-07 00:43
HTTP/1.1 403 Forbidden
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Wed, 07 Jan 2026 00:43:44 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=%2BSq55VH59bofC5oA7TDZDgKfHXU86v9RH6qnmEF0xSQ%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767746624"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=%2BSq55VH59bofC5oA7TDZDgKfHXU86v9RH6qnmEF0xSQ%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767746624"
Server: Heroku
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 99.83.217.1:80 · api.fantati.it
2026-01-07 00:43
HTTP/1.1 403 Forbidden
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Wed, 07 Jan 2026 00:44:45 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=GhIxlBSAH%2FhgZtUTtlyzk9Yd4jvGWF6O0qUYyrq9UE0%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767746685"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=GhIxlBSAH%2FhgZtUTtlyzk9Yd4jvGWF6O0qUYyrq9UE0%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767746685"
Server: Heroku
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 76.223.11.49:443 · api.fantati.it
2026-01-07 00:43
HTTP/1.1 403 Forbidden
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Wed, 07 Jan 2026 00:43:44 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=%2BSq55VH59bofC5oA7TDZDgKfHXU86v9RH6qnmEF0xSQ%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767746624"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=%2BSq55VH59bofC5oA7TDZDgKfHXU86v9RH6qnmEF0xSQ%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767746624"
Server: Heroku
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 15.197.129.158:443 · api.fantati.it
2026-01-07 00:43
HTTP/1.1 403 Forbidden
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Wed, 07 Jan 2026 00:43:43 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=lZbQhiLb3VTzUDxlvgHRQAnX6qL1T5%2FS4WyZG0EZMhU%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767746623"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=lZbQhiLb3VTzUDxlvgHRQAnX6qL1T5%2FS4WyZG0EZMhU%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767746623"
Server: Heroku
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 15.197.129.158:80 · api.fantati.it
2026-01-07 00:43
HTTP/1.1 403 Forbidden
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Wed, 07 Jan 2026 00:44:44 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=1eUilJlSMP3ep3uNa%2Fsq7c8E59nlxh56Gq%2FhuqlPB5U%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767746684"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=1eUilJlSMP3ep3uNa%2Fsq7c8E59nlxh56Gq%2FhuqlPB5U%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767746684"
Server: Heroku
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 15.197.129.158:443 · api.fantati.it
2026-01-02 20:27
HTTP/1.1 403 Forbidden
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Fri, 02 Jan 2026 20:27:56 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=qneCbWvRsbP6OwbYzdmgDnwVQdP5UUrSW01nwOvPcfc%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767385676"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=qneCbWvRsbP6OwbYzdmgDnwVQdP5UUrSW01nwOvPcfc%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767385676"
Server: Heroku
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 75.2.43.161:80 · api.fantati.it
2026-01-02 06:47
HTTP/1.1 403 Forbidden
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Fri, 02 Jan 2026 06:48:01 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=aVFkU2BEM96IZMTWRPqNmb0Xwkeg5gc8gYf52rWqAMk%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767336481"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=aVFkU2BEM96IZMTWRPqNmb0Xwkeg5gc8gYf52rWqAMk%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767336481"
Server: Heroku
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 75.2.43.161:80 · api.fantati.it
2025-12-30 10:15
HTTP/1.1 403 Forbidden
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Tue, 30 Dec 2025 10:15:26 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=ea18QjVhqDjS8GtO5yCyTC5onr%2BWv0kvmXuGvFgb%2Bh4%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767089726"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=ea18QjVhqDjS8GtO5yCyTC5onr%2BWv0kvmXuGvFgb%2Bh4%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767089726"
Server: Heroku
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 75.2.43.161:80 · api.fantati.it
2025-12-23 08:58
HTTP/1.1 403 Forbidden
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Tue, 23 Dec 2025 08:58:48 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=LJg%2BYzOLPd5wBbEghDGKqM%2FOq6Ux70A3zRSguc%2BROr8%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766480328"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=LJg%2BYzOLPd5wBbEghDGKqM%2FOq6Ux70A3zRSguc%2BROr8%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766480328"
Server: Heroku
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 15.197.129.158:443 · api.fantati.it
2025-12-22 19:44
HTTP/1.1 403 Forbidden
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Mon, 22 Dec 2025 19:44:37 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=b9cmNejk1%2FD2AaR65ckY0cJCeCbCUt%2BqZW59KTmxj7w%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766432677"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=b9cmNejk1%2FD2AaR65ckY0cJCeCbCUt%2BqZW59KTmxj7w%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766432677"
Server: Heroku
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 75.2.43.161:80 · api.fantati.it
2025-12-21 06:13
HTTP/1.1 403 Forbidden
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Sun, 21 Dec 2025 06:13:18 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=FpL13pruYMoEORZF6o1Yx9TpA7wORwu1L05NlYUwkjk%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766297598"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=FpL13pruYMoEORZF6o1Yx9TpA7wORwu1L05NlYUwkjk%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766297598"
Server: Heroku
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 15.197.129.158:443 · api.fantati.it
2025-12-20 19:44
HTTP/1.1 403 Forbidden
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Sat, 20 Dec 2025 19:44:25 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=LzMw4wRCXpLWuRk2obtaAjJLZUthN1erBkcpd09PuLY%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766259865"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=LzMw4wRCXpLWuRk2obtaAjJLZUthN1erBkcpd09PuLY%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766259865"
Server: Heroku
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 75.2.43.161:80 · api.fantati.it
2025-12-19 07:06
HTTP/1.1 403 Forbidden
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Fri, 19 Dec 2025 07:06:41 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=1LRYB1hcDINCRvPTcg0lRmW0iZsRvdjxIvuSNIgoVOU%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766128001"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=1LRYB1hcDINCRvPTcg0lRmW0iZsRvdjxIvuSNIgoVOU%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766128001"
Server: Heroku
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close