GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa33ca548bb212b2d39b9f65d9c885d971d35dfe08e
GraphQL introspection enabled at /graphql Types: 50 (by kind: ENUM: 2, INPUT_OBJECT: 10, OBJECT: 34, SCALAR: 4) Operations: - Query: Query | fields: card, cardList, deck, deckList, editions - Mutation: Mutation | fields: changeUserImg, changeUsername, createDeck, deleteDeck, updateDeck Directives: defer, deprecated, experimental_disableErrorPropagation, include, oneOf, skip, specifiedBy (total: 7)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa36c0ae24e36d656beae814df101d2eb6898645729
GraphQL introspection enabled at /graphql Types: 48 (by kind: ENUM: 2, INPUT_OBJECT: 10, OBJECT: 32, SCALAR: 4) Operations: - Query: Query | fields: card, cardList, deck, deckList, editions - Mutation: Mutation | fields: changeUserImg, changeUsername, createDeck, deleteDeck, updateDeck Directives: defer, deprecated, experimental_disableErrorPropagation, include, oneOf, skip, specifiedBy (total: 7)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3203981a6b02667d6ee22ef19e3ec4e90d8559fa1
GraphQL introspection enabled at /graphql Types: 46 (by kind: ENUM: 2, INPUT_OBJECT: 10, OBJECT: 30, SCALAR: 4) Operations: - Query: Query | fields: card, cardList, deck, deckList, editions - Mutation: Mutation | fields: changeUserImg, changeUsername, createDeck, deleteDeck, updateDeck Directives: defer, deprecated, experimental_disableErrorPropagation, include, oneOf, skip, specifiedBy (total: 7)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3769a9aacf241ccb0e100153bb3935592a93e9557
GraphQL introspection enabled at /graphql Types: 41 (by kind: ENUM: 2, INPUT_OBJECT: 8, OBJECT: 27, SCALAR: 4) Operations: - Query: Query | fields: card, cardList, deck, deckList, editions - Mutation: Mutation | fields: changeUserImg, changeUsername, createDeck, deleteDeck, updateDeck Directives: defer, deprecated, experimental_disableErrorPropagation, include, oneOf, skip, specifiedBy (total: 7)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa326c1ac3628c002a61bbe1d4911f0a4c9ebd22a72
GraphQL introspection enabled at /graphql Types: 40 (by kind: ENUM: 2, INPUT_OBJECT: 8, OBJECT: 26, SCALAR: 4) Operations: - Query: Query | fields: card, cardList, deck, deckList, editions - Mutation: Mutation | fields: addSetCard, changeUsername, createDeck, deleteDeck, updateDeck Directives: defer, deprecated, experimental_disableErrorPropagation, include, oneOf, skip, specifiedBy (total: 7)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3e0b3aad1e08c76134437e396eca4c36c8c3f46c5
GraphQL introspection enabled at /graphql Types: 39 (by kind: ENUM: 2, INPUT_OBJECT: 8, OBJECT: 25, SCALAR: 4) Operations: - Query: Query | fields: card, cardList, deck, deckList, editions - Mutation: Mutation | fields: addSetCard, changeUsername, createDeck, deleteDeck, updateDeck Directives: defer, deprecated, experimental_disableErrorPropagation, include, oneOf, skip, specifiedBy (total: 7)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3d6c7757da0ddcd9fb6e7d6a2a5b49f90e56c62a1
GraphQL introspection enabled at /graphql Types: 38 (by kind: ENUM: 2, INPUT_OBJECT: 7, OBJECT: 25, SCALAR: 4) Operations: - Query: Query | fields: card, cardList, deck, deckList, editions - Mutation: Mutation | fields: addSetCard, changeUsername, createDeck, deleteDeck, updateDeck Directives: defer, deprecated, experimental_disableErrorPropagation, include, oneOf, skip, specifiedBy (total: 7)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3f9475235340a04b70f746beaab54cee826c4d9a9
GraphQL introspection enabled at /graphql Types: 37 (by kind: ENUM: 2, INPUT_OBJECT: 7, OBJECT: 25, SCALAR: 3) Operations: - Query: Query | fields: card, cardList, deck, deckList, editions - Mutation: Mutation | fields: addSetCard, changeUsername, createDeck, deleteDeck, updateDeck Directives: defer, deprecated, experimental_disableErrorPropagation, include, oneOf, skip, specifiedBy (total: 7)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3c0e6fc87bc57df35cc7b19c8e7ced7893e5d7c32
GraphQL introspection enabled at /graphql Types: 43 (by kind: ENUM: 2, INPUT_OBJECT: 8, OBJECT: 30, SCALAR: 3) Operations: - Query: Query | fields: card, cardList, deck, deckList, editions - Mutation: Mutation | fields: changeUsername, createDeck, createEvent, deleteDeck, updateDeck Directives: defer, deprecated, experimental_disableErrorPropagation, include, oneOf, skip, specifiedBy (total: 7)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3f39569db3817e4991225787cb3fb1dd5fd86dbf2
GraphQL introspection enabled at /graphql Types: 39 (by kind: ENUM: 2, INPUT_OBJECT: 8, OBJECT: 26, SCALAR: 3) Operations: - Query: Query | fields: card, cardList, deck, deckList, editions - Mutation: Mutation | fields: changeUsername, createDeck, createEvent, deleteDeck, updateDeck Directives: defer, deprecated, experimental_disableErrorPropagation, include, oneOf, skip, specifiedBy (total: 7) Readable stores: 0
Open service 172.217.208.121:443 · api.rifty.app
2026-01-09 17:27
HTTP/1.1 302 Found vary: Origin vary: Access-Control-Request-Method vary: Access-Control-Request-Headers x-content-type-options: nosniff x-xss-protection: 0 cache-control: no-cache, no-store, max-age=0, must-revalidate pragma: no-cache expires: 0 x-frame-options: DENY set-cookie: SESSION=MzZhNzRiYzMtYmY5NS00NTJiLWEzY2EtMTAzYWMwZTgyN2Q1; Path=/; HttpOnly; SameSite=Lax location: http://api.rifty.app/login x-cloud-trace-context: fe1e974e8495e3617e870404d60a2388 date: Fri, 09 Jan 2026 17:27:38 GMT content-type: text/html server: Google Frontend Content-Length: 0 Connection: close
Open service 172.217.208.121:443 · api.rifty.app
2026-01-02 09:01
HTTP/1.1 302 Found vary: Origin vary: Access-Control-Request-Method vary: Access-Control-Request-Headers x-content-type-options: nosniff x-xss-protection: 0 cache-control: no-cache, no-store, max-age=0, must-revalidate pragma: no-cache expires: 0 x-frame-options: DENY set-cookie: SESSION=YjdlNjllYWYtNmU0Yy00MTY2LTlmMGItMzk3NjlhMTRmNWM0; Path=/; HttpOnly; SameSite=Lax location: http://api.rifty.app/login x-cloud-trace-context: e6aac8c46e236d91b0a47eb160b883ed date: Fri, 02 Jan 2026 09:01:42 GMT content-type: text/html server: Google Frontend Content-Length: 0 Connection: close
Open service 172.217.208.121:443 · api.rifty.app
2025-12-22 21:21
HTTP/1.1 302 Found vary: Origin vary: Access-Control-Request-Method vary: Access-Control-Request-Headers x-content-type-options: nosniff x-xss-protection: 0 cache-control: no-cache, no-store, max-age=0, must-revalidate pragma: no-cache expires: 0 x-frame-options: DENY set-cookie: SESSION=MWNlZjI1NzUtMzY2Yi00MTMzLWFkZWEtNGNkYjQzMmYzMjRk; Path=/; HttpOnly; SameSite=Lax location: http://api.rifty.app/login x-cloud-trace-context: a19db236d1f32dd431022ce130d96bc4 date: Mon, 22 Dec 2025 21:21:23 GMT content-type: text/html server: Google Frontend Content-Length: 0 Connection: close
Open service 172.217.208.121:443 · api.rifty.app
2025-12-20 22:59
HTTP/1.1 302 Found vary: Origin vary: Access-Control-Request-Method vary: Access-Control-Request-Headers x-content-type-options: nosniff x-xss-protection: 0 cache-control: no-cache, no-store, max-age=0, must-revalidate pragma: no-cache expires: 0 x-frame-options: DENY set-cookie: SESSION=MDQyZDE4OGUtYTA3My00ODRmLTg1YTQtNDc3NTMxYjU0ZGUx; Path=/; HttpOnly; SameSite=Lax location: http://api.rifty.app/login x-cloud-trace-context: d4726cd25fe720e89ae669f39fe2f573 date: Sat, 20 Dec 2025 22:59:38 GMT content-type: text/html server: Google Frontend Content-Length: 0 Connection: close
Open service 172.217.208.121:443 · api.rifty.app
2025-12-19 01:51
HTTP/1.1 302 Found vary: Origin vary: Access-Control-Request-Method vary: Access-Control-Request-Headers x-content-type-options: nosniff x-xss-protection: 0 cache-control: no-cache, no-store, max-age=0, must-revalidate pragma: no-cache expires: 0 x-frame-options: DENY set-cookie: SESSION=YzFkOWQ3OTItZWE3YS00ZmY5LTljNmUtYjYwYzQ5Nzc2ZjYx; Path=/; HttpOnly; SameSite=Lax location: http://api.rifty.app/login x-cloud-trace-context: b64450aefe339b1b8491685880c8f29d date: Fri, 19 Dec 2025 01:51:01 GMT content-type: text/html server: Google Frontend Content-Length: 0 Connection: close