Heroku
tcp/443 tcp/80
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa346294c995e242dfbcfb9a76923a9a8ae0db9216a
GraphQL introspection enabled at /graphql Types: 128 (by kind: ENUM: 2, INPUT_OBJECT: 59, OBJECT: 59, SCALAR: 8) Operations: - Query: Query | fields: assignmentCandidates, banners, categories, closestDeliveryDateForGoods, customer - Mutation: Mutation | fields: accountDelete, activateCustomer, addBottleToOrder, addWaiting, applyCoupon Directives: deprecated, include, skip (total: 3) Readable stores: 0
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa346294c995e242dfbcfb9a76923a9a8ae0db9216a
GraphQL introspection enabled at /graphql Types: 128 (by kind: ENUM: 2, INPUT_OBJECT: 59, OBJECT: 59, SCALAR: 8) Operations: - Query: Query | fields: assignmentCandidates, banners, categories, closestDeliveryDateForGoods, customer - Mutation: Mutation | fields: accountDelete, activateCustomer, addBottleToOrder, addWaiting, applyCoupon Directives: deprecated, include, skip (total: 3) Readable stores: 0
Open service 15.197.149.68:443 · api.stg.paradise-nature.wine
2026-01-09 19:59
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Type: text/html; charset=utf-8
Location: https://api.stg.paradise-nature.wine/auth
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=c03%2BTORnJQmqxdw0sGYmWub1dPvnt5%2FtThX9K8J8Q4I%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767988764"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=c03%2BTORnJQmqxdw0sGYmWub1dPvnt5%2FtThX9K8J8Q4I%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767988764"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 96c5d6e1-ebfe-ceae-a3a2-a7e8db2eb8d5
X-Runtime: 0.004382
X-Xss-Protection: 0
Date: Fri, 09 Jan 2026 19:59:24 GMT
Content-Length: 107
Connection: close
<html><body>You are being <a href="https://api.stg.paradise-nature.wine/auth">redirected</a>.</body></html>
Open service 3.33.241.96:80 · api.stg.paradise-nature.wine
2026-01-09 08:19
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Type: text/html; charset=utf-8
Location: http://api.stg.paradise-nature.wine/auth
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=64BR9e2r7NnNhEZlMaSQ0sYp7%2FNhxNkwXbIM%2B%2F%2B2Gsg%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767946855"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=64BR9e2r7NnNhEZlMaSQ0sYp7%2FNhxNkwXbIM%2B%2F%2B2Gsg%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767946855"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 36212c87-9c08-fa36-9094-08b92ab2545d
X-Runtime: 0.004822
X-Xss-Protection: 0
Date: Fri, 09 Jan 2026 08:20:55 GMT
Content-Length: 106
Connection: close
<html><body>You are being <a href="http://api.stg.paradise-nature.wine/auth">redirected</a>.</body></html>
Open service 15.197.149.68:443 · api.stg.paradise-nature.wine
2026-01-03 01:08
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Type: text/html; charset=utf-8
Location: https://api.stg.paradise-nature.wine/auth
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=7oRPlPnKLURbfy6Fm3k%2FYaEPmoe6paqyFu79nX0ucgw%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767402497"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=7oRPlPnKLURbfy6Fm3k%2FYaEPmoe6paqyFu79nX0ucgw%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767402497"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: d33481d2-73dc-06c3-5bbe-33b8265446a5
X-Runtime: 0.003740
X-Xss-Protection: 0
Date: Sat, 03 Jan 2026 01:08:17 GMT
Content-Length: 107
Connection: close
<html><body>You are being <a href="https://api.stg.paradise-nature.wine/auth">redirected</a>.</body></html>
Open service 3.33.241.96:80 · api.stg.paradise-nature.wine
2026-01-02 11:56
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Type: text/html; charset=utf-8
Location: http://api.stg.paradise-nature.wine/auth
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=GC8VQUQQPWAln6fa8m89haaj8VgJ5fUjnei8UvXx2eA%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767354987"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=GC8VQUQQPWAln6fa8m89haaj8VgJ5fUjnei8UvXx2eA%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767354987"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 0c07dd59-efff-e5cc-9df1-93f12ae1d7b2
X-Runtime: 0.003651
X-Xss-Protection: 0
Date: Fri, 02 Jan 2026 11:56:27 GMT
Content-Length: 106
Connection: close
<html><body>You are being <a href="http://api.stg.paradise-nature.wine/auth">redirected</a>.</body></html>
Open service 15.197.149.68:443 · api.stg.paradise-nature.wine
2025-12-30 14:41
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Type: text/html; charset=utf-8
Location: https://api.stg.paradise-nature.wine/auth
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=pWnyV%2FY0q17ffg7bcmxA4C04rd84TYzVjAFE2vwf9vU%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767105716"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=pWnyV%2FY0q17ffg7bcmxA4C04rd84TYzVjAFE2vwf9vU%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767105716"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: c6466b58-e7df-b801-9d4e-546e9575662c
X-Runtime: 0.003887
X-Xss-Protection: 0
Date: Tue, 30 Dec 2025 14:41:56 GMT
Content-Length: 107
Connection: close
<html><body>You are being <a href="https://api.stg.paradise-nature.wine/auth">redirected</a>.</body></html>
Open service 3.33.241.96:80 · api.stg.paradise-nature.wine
2025-12-22 20:00
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Type: text/html; charset=utf-8
Location: http://api.stg.paradise-nature.wine/auth
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=KpEmkD8X1Okg856GpWyEVCWeX%2BX3pJjaFohkkjeebsE%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766433647"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=KpEmkD8X1Okg856GpWyEVCWeX%2BX3pJjaFohkkjeebsE%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766433647"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: dc210618-e451-dad9-d9ed-be13f4c8c2d4
X-Runtime: 0.004068
X-Xss-Protection: 0
Date: Mon, 22 Dec 2025 20:00:47 GMT
Content-Length: 106
Connection: close
<html><body>You are being <a href="http://api.stg.paradise-nature.wine/auth">redirected</a>.</body></html>
Open service 15.197.149.68:443 · api.stg.paradise-nature.wine
2025-12-22 10:49
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Type: text/html; charset=utf-8
Location: https://api.stg.paradise-nature.wine/auth
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=hHFy9XPBS2MjRDFCErhzZuc6XnG5dtCVobQQg8WCLuU%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766400580"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=hHFy9XPBS2MjRDFCErhzZuc6XnG5dtCVobQQg8WCLuU%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766400580"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 3ac8670c-778d-e816-482d-32bca3057a89
X-Runtime: 0.004050
X-Xss-Protection: 0
Date: Mon, 22 Dec 2025 10:49:40 GMT
Content-Length: 107
Connection: close
<html><body>You are being <a href="https://api.stg.paradise-nature.wine/auth">redirected</a>.</body></html>
Open service 15.197.149.68:443 · api.stg.paradise-nature.wine
2025-12-21 10:49
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Type: text/html; charset=utf-8
Location: https://api.stg.paradise-nature.wine/auth
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=4hJU2Zd8qW1vq8DBMras%2B7qAAYaQltkKUx4%2B8TAHycw%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766314184"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=4hJU2Zd8qW1vq8DBMras%2B7qAAYaQltkKUx4%2B8TAHycw%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766314184"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: de3cc01c-e259-6636-d303-a89b96fbe5db
X-Runtime: 0.003833
X-Xss-Protection: 0
Date: Sun, 21 Dec 2025 10:49:44 GMT
Content-Length: 107
Connection: close
<html><body>You are being <a href="https://api.stg.paradise-nature.wine/auth">redirected</a>.</body></html>
Open service 3.33.241.96:80 · api.stg.paradise-nature.wine
2025-12-21 04:20
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Type: text/html; charset=utf-8
Location: http://api.stg.paradise-nature.wine/auth
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=awf0CuiErgqtLP0RxW%2BsbP9xPHUmIOT19BhR8y15RZk%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766290835"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=awf0CuiErgqtLP0RxW%2BsbP9xPHUmIOT19BhR8y15RZk%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766290835"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 580d4b1b-fc17-d7e6-2d5f-c9acc8816350
X-Runtime: 0.004021
X-Xss-Protection: 0
Date: Sun, 21 Dec 2025 04:20:35 GMT
Content-Length: 106
Connection: close
<html><body>You are being <a href="http://api.stg.paradise-nature.wine/auth">redirected</a>.</body></html>
Open service 15.197.149.68:443 · api.stg.paradise-nature.wine
2025-12-19 08:42
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Type: text/html; charset=utf-8
Location: https://api.stg.paradise-nature.wine/auth
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=nt2Gm3WxLNMGRrd1rBHKiPi6Xa6yg5fgkXuOAawpYr4%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766133765"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=nt2Gm3WxLNMGRrd1rBHKiPi6Xa6yg5fgkXuOAawpYr4%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766133765"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: ff65aa63-ef07-6434-f4c5-92c6a15ba48f
X-Runtime: 0.004573
X-Xss-Protection: 0
Date: Fri, 19 Dec 2025 08:42:45 GMT
Content-Length: 107
Connection: close
<html><body>You are being <a href="https://api.stg.paradise-nature.wine/auth">redirected</a>.</body></html>
Open service 3.33.241.96:80 · api.stg.paradise-nature.wine
2025-12-19 04:28
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Type: text/html; charset=utf-8
Location: http://api.stg.paradise-nature.wine/auth
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=KDbFeuMf661RRaXDJjY16fFEVnKHkwI2m6Zn%2BgeG7dE%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766118524"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=KDbFeuMf661RRaXDJjY16fFEVnKHkwI2m6Zn%2BgeG7dE%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766118524"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 0fb76ec8-aea0-dfa2-f5d4-3ff346a5bab4
X-Runtime: 0.003799
X-Xss-Protection: 0
Date: Fri, 19 Dec 2025 04:28:44 GMT
Content-Length: 106
Connection: close
<html><body>You are being <a href="http://api.stg.paradise-nature.wine/auth">redirected</a>.</body></html>