Heroku
tcp/443 tcp/80
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa327c391d5fb244e9704eb68845ec9aee253f436ee
GraphQL introspection enabled at /graphql Types: 509 (by kind: ENUM: 51, INPUT_OBJECT: 219, INTERFACE: 3, OBJECT: 222, SCALAR: 6, UNION: 8) Operations: - Query: Query | fields: allocations, emailFunnel, segmentation, smsFunnel, weekdays - Mutation: Mutation | fields: createAllocation, deleteAllocation, setAllocationVisibility, signInWithEmail, updateAllocation - Subscription: Subscription | fields: emailAssistantResponse Directives: auth, deprecated, include, oneOf, skip, specifiedBy (total: 6)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa371421ba1ed89fd63261b24587bdcd76ef21c6b7a
GraphQL introspection enabled at /graphql Types: 506 (by kind: ENUM: 51, INPUT_OBJECT: 218, INTERFACE: 3, OBJECT: 220, SCALAR: 6, UNION: 8) Operations: - Query: Query | fields: allocations, emailFunnel, segmentation, smsFunnel, weekdays - Mutation: Mutation | fields: createAllocation, deleteAllocation, setAllocationVisibility, signInWithEmail, updateAllocation - Subscription: Subscription | fields: emailAssistantResponse Directives: auth, deprecated, include, oneOf, skip, specifiedBy (total: 6)
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa327c391d5fb244e9704eb68845ec9aee253f436ee
GraphQL introspection enabled at /graphql Types: 509 (by kind: ENUM: 51, INPUT_OBJECT: 219, INTERFACE: 3, OBJECT: 222, SCALAR: 6, UNION: 8) Operations: - Query: Query | fields: allocations, emailFunnel, segmentation, smsFunnel, weekdays - Mutation: Mutation | fields: createAllocation, deleteAllocation, setAllocationVisibility, signInWithEmail, updateAllocation - Subscription: Subscription | fields: emailAssistantResponse Directives: auth, deprecated, include, oneOf, skip, specifiedBy (total: 6)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa371421ba1ed89fd63261b24587bdcd76ef21c6b7a
GraphQL introspection enabled at /graphql Types: 506 (by kind: ENUM: 51, INPUT_OBJECT: 218, INTERFACE: 3, OBJECT: 220, SCALAR: 6, UNION: 8) Operations: - Query: Query | fields: allocations, emailFunnel, segmentation, smsFunnel, weekdays - Mutation: Mutation | fields: createAllocation, deleteAllocation, setAllocationVisibility, signInWithEmail, updateAllocation - Subscription: Subscription | fields: emailAssistantResponse Directives: auth, deprecated, include, oneOf, skip, specifiedBy (total: 6)
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa367053df25c4beb02cc61be19c9447e6dcb53d5f7
GraphQL introspection enabled at /graphql Types: 501 (by kind: ENUM: 50, INPUT_OBJECT: 218, INTERFACE: 3, OBJECT: 216, SCALAR: 6, UNION: 8) Operations: - Query: Query | fields: allocations, emailFunnel, segmentation, smsFunnel, weekdays - Mutation: Mutation | fields: createAllocation, deleteAllocation, setAllocationVisibility, signInWithEmail, updateAllocation - Subscription: Subscription | fields: emailAssistantResponse Directives: auth, deprecated, include, oneOf, skip, specifiedBy (total: 6)
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa367053df25c4beb02cc61be19c9447e6dcb53d5f7
GraphQL introspection enabled at /graphql Types: 501 (by kind: ENUM: 50, INPUT_OBJECT: 218, INTERFACE: 3, OBJECT: 216, SCALAR: 6, UNION: 8) Operations: - Query: Query | fields: allocations, emailFunnel, segmentation, smsFunnel, weekdays - Mutation: Mutation | fields: createAllocation, deleteAllocation, setAllocationVisibility, signInWithEmail, updateAllocation - Subscription: Subscription | fields: emailAssistantResponse Directives: auth, deprecated, include, oneOf, skip, specifiedBy (total: 6)
Open service 99.83.220.108:80 · api.kindest.com
2026-01-09 20:29
HTTP/1.1 400 Bad Request
Access-Control-Allow-Origin: *
Content-Length: 406
Content-Type: application/json; charset=utf-8
Date: Fri, 09 Jan 2026 20:30:52 GMT
Etag: W/"196-HUCJKwlQurC5GNaaJnH0d+HOnRw"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=sVLFAs4NeV2OndkxGqO%2BIKoTJ2Qh5JMZmi9ZrOi2kWk%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767990652"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=sVLFAs4NeV2OndkxGqO%2BIKoTJ2Qh5JMZmi9ZrOi2kWk%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767990652"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
{"errors":[{"message":"This operation has been blocked as a potential Cross-Site Request Forgery (CSRF). Please either specify a 'content-type' header (with a type that is not one of application/x-www-form-urlencoded, multipart/form-data, text/plain) or provide a non-empty value for one of the following headers: x-apollo-operation-name, apollo-require-preflight\n","extensions":{"code":"BAD_REQUEST"}}]}
Open service 35.71.179.82:80 · staging.api.kindest.com
2026-01-09 12:49
HTTP/1.1 400 Bad Request
Access-Control-Allow-Origin: *
Content-Length: 406
Content-Type: application/json; charset=utf-8
Date: Fri, 09 Jan 2026 12:50:44 GMT
Etag: W/"196-HUCJKwlQurC5GNaaJnH0d+HOnRw"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=rrUnG7vDDBJi%2F7ZlGclbNWYGHRYpBmavJNpz4LlJDL8%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767963044"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=rrUnG7vDDBJi%2F7ZlGclbNWYGHRYpBmavJNpz4LlJDL8%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767963044"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
{"errors":[{"message":"This operation has been blocked as a potential Cross-Site Request Forgery (CSRF). Please either specify a 'content-type' header (with a type that is not one of application/x-www-form-urlencoded, multipart/form-data, text/plain) or provide a non-empty value for one of the following headers: x-apollo-operation-name, apollo-require-preflight\n","extensions":{"code":"BAD_REQUEST"}}]}
Open service 75.2.60.68:443 · staging.api.kindest.com
2026-01-09 06:04
HTTP/1.1 400 Bad Request
Access-Control-Allow-Origin: *
Content-Length: 406
Content-Type: application/json; charset=utf-8
Date: Fri, 09 Jan 2026 06:04:06 GMT
Etag: W/"196-HUCJKwlQurC5GNaaJnH0d+HOnRw"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=bZttg6u%2BxCeS%2BGOuH%2BbE37FSEvJicsM5QXHt35WuiVo%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767938646"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=bZttg6u%2BxCeS%2BGOuH%2BbE37FSEvJicsM5QXHt35WuiVo%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767938646"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
{"errors":[{"message":"This operation has been blocked as a potential Cross-Site Request Forgery (CSRF). Please either specify a 'content-type' header (with a type that is not one of application/x-www-form-urlencoded, multipart/form-data, text/plain) or provide a non-empty value for one of the following headers: x-apollo-operation-name, apollo-require-preflight\n","extensions":{"code":"BAD_REQUEST"}}]}
Open service 75.2.60.68:443 · api.kindest.com
2026-01-09 06:00
HTTP/1.1 400 Bad Request
Access-Control-Allow-Origin: *
Content-Length: 406
Content-Type: application/json; charset=utf-8
Date: Fri, 09 Jan 2026 06:00:20 GMT
Etag: W/"196-HUCJKwlQurC5GNaaJnH0d+HOnRw"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=0rGETJe76lMZ5whOli4ft%2F7tvy58yFZVEmsVWQ6Gmws%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767938420"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=0rGETJe76lMZ5whOli4ft%2F7tvy58yFZVEmsVWQ6Gmws%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767938420"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
{"errors":[{"message":"This operation has been blocked as a potential Cross-Site Request Forgery (CSRF). Please either specify a 'content-type' header (with a type that is not one of application/x-www-form-urlencoded, multipart/form-data, text/plain) or provide a non-empty value for one of the following headers: x-apollo-operation-name, apollo-require-preflight\n","extensions":{"code":"BAD_REQUEST"}}]}
Open service 99.83.220.108:80 · api.kindest.com
2026-01-03 00:38
HTTP/1.1 400 Bad Request
Access-Control-Allow-Origin: *
Content-Length: 406
Content-Type: application/json; charset=utf-8
Date: Sat, 03 Jan 2026 00:38:16 GMT
Etag: W/"196-HUCJKwlQurC5GNaaJnH0d+HOnRw"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=WA1Ffvp2gd%2FU4pIlcHFdi9U5Bn8JV8KIOYDtgs%2BuAg8%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767400696"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=WA1Ffvp2gd%2FU4pIlcHFdi9U5Bn8JV8KIOYDtgs%2BuAg8%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767400696"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
{"errors":[{"message":"This operation has been blocked as a potential Cross-Site Request Forgery (CSRF). Please either specify a 'content-type' header (with a type that is not one of application/x-www-form-urlencoded, multipart/form-data, text/plain) or provide a non-empty value for one of the following headers: x-apollo-operation-name, apollo-require-preflight\n","extensions":{"code":"BAD_REQUEST"}}]}
Open service 75.2.60.68:443 · api.kindest.com
2026-01-02 04:35
HTTP/1.1 400 Bad Request
Access-Control-Allow-Origin: *
Content-Length: 406
Content-Type: application/json; charset=utf-8
Date: Fri, 02 Jan 2026 04:35:25 GMT
Etag: W/"196-HUCJKwlQurC5GNaaJnH0d+HOnRw"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=Zs%2F8d24dOvDSH4soSX2LMAEceCIyeTa0hvJxjuPEty0%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767328525"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=Zs%2F8d24dOvDSH4soSX2LMAEceCIyeTa0hvJxjuPEty0%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767328525"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
{"errors":[{"message":"This operation has been blocked as a potential Cross-Site Request Forgery (CSRF). Please either specify a 'content-type' header (with a type that is not one of application/x-www-form-urlencoded, multipart/form-data, text/plain) or provide a non-empty value for one of the following headers: x-apollo-operation-name, apollo-require-preflight\n","extensions":{"code":"BAD_REQUEST"}}]}
Open service 75.2.60.68:443 · staging.api.kindest.com
2026-01-02 04:32
HTTP/1.1 400 Bad Request
Access-Control-Allow-Origin: *
Content-Length: 406
Content-Type: application/json; charset=utf-8
Date: Fri, 02 Jan 2026 04:32:12 GMT
Etag: W/"196-HUCJKwlQurC5GNaaJnH0d+HOnRw"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=YKlo76G6qCl3mhIk9WU80n8mU2Nqf%2BgNhNVbGXgnZdk%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767328332"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=YKlo76G6qCl3mhIk9WU80n8mU2Nqf%2BgNhNVbGXgnZdk%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767328332"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
{"errors":[{"message":"This operation has been blocked as a potential Cross-Site Request Forgery (CSRF). Please either specify a 'content-type' header (with a type that is not one of application/x-www-form-urlencoded, multipart/form-data, text/plain) or provide a non-empty value for one of the following headers: x-apollo-operation-name, apollo-require-preflight\n","extensions":{"code":"BAD_REQUEST"}}]}
Open service 35.71.179.82:80 · staging.api.kindest.com
2026-01-02 01:41
HTTP/1.1 400 Bad Request
Access-Control-Allow-Origin: *
Content-Length: 406
Content-Type: application/json; charset=utf-8
Date: Fri, 02 Jan 2026 01:41:35 GMT
Etag: W/"196-HUCJKwlQurC5GNaaJnH0d+HOnRw"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=YXPZg74sSJu%2BcLm971PC9z4SyxWxvJo5xHwOqiAh%2BhU%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767318095"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=YXPZg74sSJu%2BcLm971PC9z4SyxWxvJo5xHwOqiAh%2BhU%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767318095"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
{"errors":[{"message":"This operation has been blocked as a potential Cross-Site Request Forgery (CSRF). Please either specify a 'content-type' header (with a type that is not one of application/x-www-form-urlencoded, multipart/form-data, text/plain) or provide a non-empty value for one of the following headers: x-apollo-operation-name, apollo-require-preflight\n","extensions":{"code":"BAD_REQUEST"}}]}
Open service 35.71.179.82:80 · staging.api.kindest.com
2025-12-30 12:30
HTTP/1.1 400 Bad Request
Access-Control-Allow-Origin: *
Content-Length: 406
Content-Type: application/json; charset=utf-8
Date: Tue, 30 Dec 2025 12:30:59 GMT
Etag: W/"196-HUCJKwlQurC5GNaaJnH0d+HOnRw"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=obD9PuKIUmiIPrW4b1v3W1J1qe%2BTMpHl8RwgseZE%2Fl0%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767097859"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=obD9PuKIUmiIPrW4b1v3W1J1qe%2BTMpHl8RwgseZE%2Fl0%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767097859"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
{"errors":[{"message":"This operation has been blocked as a potential Cross-Site Request Forgery (CSRF). Please either specify a 'content-type' header (with a type that is not one of application/x-www-form-urlencoded, multipart/form-data, text/plain) or provide a non-empty value for one of the following headers: x-apollo-operation-name, apollo-require-preflight\n","extensions":{"code":"BAD_REQUEST"}}]}
Open service 99.83.220.108:80 · api.kindest.com
2025-12-23 08:06
HTTP/1.1 400 Bad Request
Access-Control-Allow-Origin: *
Content-Length: 406
Content-Type: application/json; charset=utf-8
Date: Tue, 23 Dec 2025 08:06:28 GMT
Etag: W/"196-HUCJKwlQurC5GNaaJnH0d+HOnRw"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=zonfzpOqVHg4ItqYEs9CN1mIZb6tYHGw20DsWLIRmlY%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766477188"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=zonfzpOqVHg4ItqYEs9CN1mIZb6tYHGw20DsWLIRmlY%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766477188"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
{"errors":[{"message":"This operation has been blocked as a potential Cross-Site Request Forgery (CSRF). Please either specify a 'content-type' header (with a type that is not one of application/x-www-form-urlencoded, multipart/form-data, text/plain) or provide a non-empty value for one of the following headers: x-apollo-operation-name, apollo-require-preflight\n","extensions":{"code":"BAD_REQUEST"}}]}
Open service 75.2.60.68:443 · staging.api.kindest.com
2025-12-22 18:54
HTTP/1.1 400 Bad Request
Access-Control-Allow-Origin: *
Content-Length: 406
Content-Type: application/json; charset=utf-8
Date: Mon, 22 Dec 2025 18:54:42 GMT
Etag: W/"196-HUCJKwlQurC5GNaaJnH0d+HOnRw"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=fvrSsb7RLtbL0r8qnsdxtI%2BC3HLoDlQQ6MGpbw6kMHs%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766429682"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=fvrSsb7RLtbL0r8qnsdxtI%2BC3HLoDlQQ6MGpbw6kMHs%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766429682"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
{"errors":[{"message":"This operation has been blocked as a potential Cross-Site Request Forgery (CSRF). Please either specify a 'content-type' header (with a type that is not one of application/x-www-form-urlencoded, multipart/form-data, text/plain) or provide a non-empty value for one of the following headers: x-apollo-operation-name, apollo-require-preflight\n","extensions":{"code":"BAD_REQUEST"}}]}
Open service 75.2.60.68:443 · api.kindest.com
2025-12-22 09:30
HTTP/1.1 400 Bad Request
Access-Control-Allow-Origin: *
Content-Length: 406
Content-Type: application/json; charset=utf-8
Date: Mon, 22 Dec 2025 09:30:13 GMT
Etag: W/"196-HUCJKwlQurC5GNaaJnH0d+HOnRw"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=LVWE338TWjZYzv%2B6UtrijDh59SKRfgKYkrTOIcW9Dgs%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766395813"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=LVWE338TWjZYzv%2B6UtrijDh59SKRfgKYkrTOIcW9Dgs%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766395813"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
{"errors":[{"message":"This operation has been blocked as a potential Cross-Site Request Forgery (CSRF). Please either specify a 'content-type' header (with a type that is not one of application/x-www-form-urlencoded, multipart/form-data, text/plain) or provide a non-empty value for one of the following headers: x-apollo-operation-name, apollo-require-preflight\n","extensions":{"code":"BAD_REQUEST"}}]}
Open service 35.71.179.82:80 · staging.api.kindest.com
2025-12-22 08:11
HTTP/1.1 400 Bad Request
Access-Control-Allow-Origin: *
Content-Length: 406
Content-Type: application/json; charset=utf-8
Date: Mon, 22 Dec 2025 08:11:25 GMT
Etag: W/"196-HUCJKwlQurC5GNaaJnH0d+HOnRw"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=%2B8XyJy8ll9o3R4%2B8ZR4%2B8yQWOoCAfKZgZI%2BL2M8RRPY%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766391085"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=%2B8XyJy8ll9o3R4%2B8ZR4%2B8yQWOoCAfKZgZI%2BL2M8RRPY%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766391085"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
{"errors":[{"message":"This operation has been blocked as a potential Cross-Site Request Forgery (CSRF). Please either specify a 'content-type' header (with a type that is not one of application/x-www-form-urlencoded, multipart/form-data, text/plain) or provide a non-empty value for one of the following headers: x-apollo-operation-name, apollo-require-preflight\n","extensions":{"code":"BAD_REQUEST"}}]}
Open service 99.83.220.108:80 · api.kindest.com
2025-12-21 03:22
HTTP/1.1 400 Bad Request
Access-Control-Allow-Origin: *
Content-Length: 406
Content-Type: application/json; charset=utf-8
Date: Sun, 21 Dec 2025 03:22:08 GMT
Etag: W/"196-HUCJKwlQurC5GNaaJnH0d+HOnRw"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=DfRFC3ibyoI0Xy0C6K8oCD6DsfsMvWtKAu8tgOdqTy0%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766287328"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=DfRFC3ibyoI0Xy0C6K8oCD6DsfsMvWtKAu8tgOdqTy0%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766287328"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
{"errors":[{"message":"This operation has been blocked as a potential Cross-Site Request Forgery (CSRF). Please either specify a 'content-type' header (with a type that is not one of application/x-www-form-urlencoded, multipart/form-data, text/plain) or provide a non-empty value for one of the following headers: x-apollo-operation-name, apollo-require-preflight\n","extensions":{"code":"BAD_REQUEST"}}]}
Open service 75.2.60.68:443 · staging.api.kindest.com
2025-12-20 20:28
HTTP/1.1 400 Bad Request
Access-Control-Allow-Origin: *
Content-Length: 406
Content-Type: application/json; charset=utf-8
Date: Sat, 20 Dec 2025 20:28:06 GMT
Etag: W/"196-HUCJKwlQurC5GNaaJnH0d+HOnRw"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=6WMpbS3vk4HKOknW61kbSv9EvpGG5NXF8ArNbuLWi9Y%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766262486"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=6WMpbS3vk4HKOknW61kbSv9EvpGG5NXF8ArNbuLWi9Y%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766262486"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
{"errors":[{"message":"This operation has been blocked as a potential Cross-Site Request Forgery (CSRF). Please either specify a 'content-type' header (with a type that is not one of application/x-www-form-urlencoded, multipart/form-data, text/plain) or provide a non-empty value for one of the following headers: x-apollo-operation-name, apollo-require-preflight\n","extensions":{"code":"BAD_REQUEST"}}]}
Open service 75.2.60.68:443 · api.kindest.com
2025-12-20 08:48
HTTP/1.1 400 Bad Request
Access-Control-Allow-Origin: *
Content-Length: 406
Content-Type: application/json; charset=utf-8
Date: Sat, 20 Dec 2025 08:48:16 GMT
Etag: W/"196-HUCJKwlQurC5GNaaJnH0d+HOnRw"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=xbBeABh9vDEzTnTnkRlyPSdToALUYCduD6OYN%2BydMJM%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766220496"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=xbBeABh9vDEzTnTnkRlyPSdToALUYCduD6OYN%2BydMJM%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766220496"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
{"errors":[{"message":"This operation has been blocked as a potential Cross-Site Request Forgery (CSRF). Please either specify a 'content-type' header (with a type that is not one of application/x-www-form-urlencoded, multipart/form-data, text/plain) or provide a non-empty value for one of the following headers: x-apollo-operation-name, apollo-require-preflight\n","extensions":{"code":"BAD_REQUEST"}}]}
Open service 35.71.179.82:80 · staging.api.kindest.com
2025-12-20 05:50
HTTP/1.1 400 Bad Request
Access-Control-Allow-Origin: *
Content-Length: 406
Content-Type: application/json; charset=utf-8
Date: Sat, 20 Dec 2025 05:50:07 GMT
Etag: W/"196-HUCJKwlQurC5GNaaJnH0d+HOnRw"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=D2tFdIEeSPuzeWcdsWsSBCdRREea676qQ3DuOh0YQJs%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766209807"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=D2tFdIEeSPuzeWcdsWsSBCdRREea676qQ3DuOh0YQJs%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766209807"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
{"errors":[{"message":"This operation has been blocked as a potential Cross-Site Request Forgery (CSRF). Please either specify a 'content-type' header (with a type that is not one of application/x-www-form-urlencoded, multipart/form-data, text/plain) or provide a non-empty value for one of the following headers: x-apollo-operation-name, apollo-require-preflight\n","extensions":{"code":"BAD_REQUEST"}}]}
Open service 35.71.179.82:80 · api.kindest.com
2025-12-20 00:27
HTTP/1.1 400 Bad Request
Access-Control-Allow-Origin: *
Content-Length: 406
Content-Type: application/json; charset=utf-8
Date: Sat, 20 Dec 2025 00:27:32 GMT
Etag: W/"196-HUCJKwlQurC5GNaaJnH0d+HOnRw"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=wpAMlAVhH%2BIg3yi1nO8nAMs5JE%2FXj3JKMibd9qAd%2B1A%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766190452"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=wpAMlAVhH%2BIg3yi1nO8nAMs5JE%2FXj3JKMibd9qAd%2B1A%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766190452"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
{"errors":[{"message":"This operation has been blocked as a potential Cross-Site Request Forgery (CSRF). Please either specify a 'content-type' header (with a type that is not one of application/x-www-form-urlencoded, multipart/form-data, text/plain) or provide a non-empty value for one of the following headers: x-apollo-operation-name, apollo-require-preflight\n","extensions":{"code":"BAD_REQUEST"}}]}
Open service 13.248.244.96:80 · api.kindest.com
2025-12-20 00:27
HTTP/1.1 400 Bad Request
Access-Control-Allow-Origin: *
Content-Length: 406
Content-Type: application/json; charset=utf-8
Date: Sat, 20 Dec 2025 00:27:31 GMT
Etag: W/"196-HUCJKwlQurC5GNaaJnH0d+HOnRw"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=CJhxVf8RDeX2PHAulGwuyvbS%2F%2Fdc9%2BZmtkP%2BqPMKwWQ%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766190451"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=CJhxVf8RDeX2PHAulGwuyvbS%2F%2Fdc9%2BZmtkP%2BqPMKwWQ%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766190451"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
{"errors":[{"message":"This operation has been blocked as a potential Cross-Site Request Forgery (CSRF). Please either specify a 'content-type' header (with a type that is not one of application/x-www-form-urlencoded, multipart/form-data, text/plain) or provide a non-empty value for one of the following headers: x-apollo-operation-name, apollo-require-preflight\n","extensions":{"code":"BAD_REQUEST"}}]}
Open service 99.83.220.108:80 · api.kindest.com
2025-12-20 00:27
HTTP/1.1 400 Bad Request
Access-Control-Allow-Origin: *
Content-Length: 406
Content-Type: application/json; charset=utf-8
Date: Sat, 20 Dec 2025 00:27:31 GMT
Etag: W/"196-HUCJKwlQurC5GNaaJnH0d+HOnRw"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=CJhxVf8RDeX2PHAulGwuyvbS%2F%2Fdc9%2BZmtkP%2BqPMKwWQ%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766190451"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=CJhxVf8RDeX2PHAulGwuyvbS%2F%2Fdc9%2BZmtkP%2BqPMKwWQ%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766190451"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
{"errors":[{"message":"This operation has been blocked as a potential Cross-Site Request Forgery (CSRF). Please either specify a 'content-type' header (with a type that is not one of application/x-www-form-urlencoded, multipart/form-data, text/plain) or provide a non-empty value for one of the following headers: x-apollo-operation-name, apollo-require-preflight\n","extensions":{"code":"BAD_REQUEST"}}]}
Open service 13.248.244.96:443 · api.kindest.com
2025-12-20 00:27
HTTP/1.1 400 Bad Request
Access-Control-Allow-Origin: *
Content-Length: 406
Content-Type: application/json; charset=utf-8
Date: Sat, 20 Dec 2025 00:27:28 GMT
Etag: W/"196-HUCJKwlQurC5GNaaJnH0d+HOnRw"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=YGR5OKmVxGDqblLrXaLlgewSqw3JEaYWBu7P5W82gZU%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766190448"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=YGR5OKmVxGDqblLrXaLlgewSqw3JEaYWBu7P5W82gZU%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766190448"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
{"errors":[{"message":"This operation has been blocked as a potential Cross-Site Request Forgery (CSRF). Please either specify a 'content-type' header (with a type that is not one of application/x-www-form-urlencoded, multipart/form-data, text/plain) or provide a non-empty value for one of the following headers: x-apollo-operation-name, apollo-require-preflight\n","extensions":{"code":"BAD_REQUEST"}}]}
Open service 35.71.179.82:443 · api.kindest.com
2025-12-20 00:27
HTTP/1.1 400 Bad Request
Access-Control-Allow-Origin: *
Content-Length: 406
Content-Type: application/json; charset=utf-8
Date: Sat, 20 Dec 2025 00:27:28 GMT
Etag: W/"196-HUCJKwlQurC5GNaaJnH0d+HOnRw"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=YGR5OKmVxGDqblLrXaLlgewSqw3JEaYWBu7P5W82gZU%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766190448"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=YGR5OKmVxGDqblLrXaLlgewSqw3JEaYWBu7P5W82gZU%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766190448"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
{"errors":[{"message":"This operation has been blocked as a potential Cross-Site Request Forgery (CSRF). Please either specify a 'content-type' header (with a type that is not one of application/x-www-form-urlencoded, multipart/form-data, text/plain) or provide a non-empty value for one of the following headers: x-apollo-operation-name, apollo-require-preflight\n","extensions":{"code":"BAD_REQUEST"}}]}
Open service 75.2.60.68:80 · api.kindest.com
2025-12-20 00:27
HTTP/1.1 400 Bad Request
Access-Control-Allow-Origin: *
Content-Length: 406
Content-Type: application/json; charset=utf-8
Date: Sat, 20 Dec 2025 00:27:31 GMT
Etag: W/"196-HUCJKwlQurC5GNaaJnH0d+HOnRw"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=CJhxVf8RDeX2PHAulGwuyvbS%2F%2Fdc9%2BZmtkP%2BqPMKwWQ%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766190451"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=CJhxVf8RDeX2PHAulGwuyvbS%2F%2Fdc9%2BZmtkP%2BqPMKwWQ%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766190451"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
{"errors":[{"message":"This operation has been blocked as a potential Cross-Site Request Forgery (CSRF). Please either specify a 'content-type' header (with a type that is not one of application/x-www-form-urlencoded, multipart/form-data, text/plain) or provide a non-empty value for one of the following headers: x-apollo-operation-name, apollo-require-preflight\n","extensions":{"code":"BAD_REQUEST"}}]}
Open service 75.2.60.68:443 · api.kindest.com
2025-12-20 00:27
HTTP/1.1 400 Bad Request
Access-Control-Allow-Origin: *
Content-Length: 406
Content-Type: application/json; charset=utf-8
Date: Sat, 20 Dec 2025 00:27:28 GMT
Etag: W/"196-HUCJKwlQurC5GNaaJnH0d+HOnRw"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=YGR5OKmVxGDqblLrXaLlgewSqw3JEaYWBu7P5W82gZU%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766190448"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=YGR5OKmVxGDqblLrXaLlgewSqw3JEaYWBu7P5W82gZU%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766190448"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
{"errors":[{"message":"This operation has been blocked as a potential Cross-Site Request Forgery (CSRF). Please either specify a 'content-type' header (with a type that is not one of application/x-www-form-urlencoded, multipart/form-data, text/plain) or provide a non-empty value for one of the following headers: x-apollo-operation-name, apollo-require-preflight\n","extensions":{"code":"BAD_REQUEST"}}]}
Open service 99.83.220.108:443 · api.kindest.com
2025-12-20 00:27
HTTP/1.1 400 Bad Request
Access-Control-Allow-Origin: *
Content-Length: 406
Content-Type: application/json; charset=utf-8
Date: Sat, 20 Dec 2025 00:27:28 GMT
Etag: W/"196-HUCJKwlQurC5GNaaJnH0d+HOnRw"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=YGR5OKmVxGDqblLrXaLlgewSqw3JEaYWBu7P5W82gZU%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766190448"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=YGR5OKmVxGDqblLrXaLlgewSqw3JEaYWBu7P5W82gZU%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766190448"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
{"errors":[{"message":"This operation has been blocked as a potential Cross-Site Request Forgery (CSRF). Please either specify a 'content-type' header (with a type that is not one of application/x-www-form-urlencoded, multipart/form-data, text/plain) or provide a non-empty value for one of the following headers: x-apollo-operation-name, apollo-require-preflight\n","extensions":{"code":"BAD_REQUEST"}}]}
Open service 99.83.220.108:80 · api.kindest.com
2025-12-19 03:07
HTTP/1.1 400 Bad Request
Access-Control-Allow-Origin: *
Content-Length: 406
Content-Type: application/json; charset=utf-8
Date: Fri, 19 Dec 2025 03:07:51 GMT
Etag: W/"196-HUCJKwlQurC5GNaaJnH0d+HOnRw"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=JeTvP5RWXj6Gj2nmpPfIeX3MFk55behUMJYcnusqGss%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766113671"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=JeTvP5RWXj6Gj2nmpPfIeX3MFk55behUMJYcnusqGss%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766113671"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
{"errors":[{"message":"This operation has been blocked as a potential Cross-Site Request Forgery (CSRF). Please either specify a 'content-type' header (with a type that is not one of application/x-www-form-urlencoded, multipart/form-data, text/plain) or provide a non-empty value for one of the following headers: x-apollo-operation-name, apollo-require-preflight\n","extensions":{"code":"BAD_REQUEST"}}]}