Heroku
tcp/443 tcp/80
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3d9181c39a346585bfbe2b3f59676f8159676f815
GraphQL introspection enabled at /graphql Types: 12 (by kind: ENUM: 2, OBJECT: 7, SCALAR: 3) Operations: - Query: Query | fields: _empty Directives: deprecated, include, skip (total: 3)
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3d9181c39a346585bfbe2b3f59676f8159676f815
GraphQL introspection enabled at /graphql Types: 12 (by kind: ENUM: 2, OBJECT: 7, SCALAR: 3) Operations: - Query: Query | fields: _empty Directives: deprecated, include, skip (total: 3)
Open service 52.223.53.203:80 · api.tsed.dev
2026-01-09 06:00
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://raw.githubusercontent.com https://avatars.githubusercontent.com;media-src 'self';connect-src 'self' https://* wss://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Fri, 09 Jan 2026 06:01:10 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=032a76QK4tZpR8bKKFJyhpmEBTdgKGxDqZZ2WMt9Ubs%3D\u0026sid=812dcc77-0bd0-43b1-a5f1-b25750382959\u0026ts=1767938470"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=032a76QK4tZpR8bKKFJyhpmEBTdgKGxDqZZ2WMt9Ubs%3D&sid=812dcc77-0bd0-43b1-a5f1-b25750382959&ts=1767938470"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 3.33.249.164:443 · api.tsed.dev
2026-01-09 02:39
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://raw.githubusercontent.com https://avatars.githubusercontent.com;media-src 'self';connect-src 'self' https://* wss://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Fri, 09 Jan 2026 02:39:03 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=MJP0bbopCXCkIF%2FcfxE09Yg%2Bpv97kQnTBz%2Bpcz1ImPk%3D\u0026sid=812dcc77-0bd0-43b1-a5f1-b25750382959\u0026ts=1767926343"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=MJP0bbopCXCkIF%2FcfxE09Yg%2Bpv97kQnTBz%2Bpcz1ImPk%3D&sid=812dcc77-0bd0-43b1-a5f1-b25750382959&ts=1767926343"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 52.223.53.203:80 · api.tsed.dev
2026-01-02 04:35
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://raw.githubusercontent.com https://avatars.githubusercontent.com;media-src 'self';connect-src 'self' https://* wss://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Fri, 02 Jan 2026 04:35:34 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=iQ5oTYpDf3piPRkFWbGdJFnMxME2n2PV1BCjfzBKRVI%3D\u0026sid=812dcc77-0bd0-43b1-a5f1-b25750382959\u0026ts=1767328534"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=iQ5oTYpDf3piPRkFWbGdJFnMxME2n2PV1BCjfzBKRVI%3D&sid=812dcc77-0bd0-43b1-a5f1-b25750382959&ts=1767328534"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 3.33.249.164:443 · api.tsed.dev
2026-01-02 00:33
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://raw.githubusercontent.com https://avatars.githubusercontent.com;media-src 'self';connect-src 'self' https://* wss://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Fri, 02 Jan 2026 00:33:17 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=eqrbMR38km8Cb7ybypMsG8pTAA4b37d8N1brmX107%2FQ%3D\u0026sid=812dcc77-0bd0-43b1-a5f1-b25750382959\u0026ts=1767313997"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=eqrbMR38km8Cb7ybypMsG8pTAA4b37d8N1brmX107%2FQ%3D&sid=812dcc77-0bd0-43b1-a5f1-b25750382959&ts=1767313997"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 3.33.249.164:443 · api.tsed.dev
2025-12-30 08:13
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://raw.githubusercontent.com https://avatars.githubusercontent.com;media-src 'self';connect-src 'self' https://* wss://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Tue, 30 Dec 2025 08:13:12 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=XWykoE2cmCJbCZEtw%2FHTUhbelWl20K07rGE0o4I0WMs%3D\u0026sid=812dcc77-0bd0-43b1-a5f1-b25750382959\u0026ts=1767082392"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=XWykoE2cmCJbCZEtw%2FHTUhbelWl20K07rGE0o4I0WMs%3D&sid=812dcc77-0bd0-43b1-a5f1-b25750382959&ts=1767082392"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 3.33.249.164:443 · api.tsed.dev
2025-12-22 23:11
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://raw.githubusercontent.com https://avatars.githubusercontent.com;media-src 'self';connect-src 'self' https://* wss://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Mon, 22 Dec 2025 23:11:23 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=skmX34Imix%2BTgBBEfKJuDg1fbecg2khc3fhpfmMwXa0%3D\u0026sid=812dcc77-0bd0-43b1-a5f1-b25750382959\u0026ts=1766445083"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=skmX34Imix%2BTgBBEfKJuDg1fbecg2khc3fhpfmMwXa0%3D&sid=812dcc77-0bd0-43b1-a5f1-b25750382959&ts=1766445083"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 52.223.53.203:80 · api.tsed.dev
2025-12-22 09:29
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://raw.githubusercontent.com https://avatars.githubusercontent.com;media-src 'self';connect-src 'self' https://* wss://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Mon, 22 Dec 2025 09:29:58 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=dAXmxloSScjS%2FZ9EIT1C%2B2SBB2h86QXaixpacFWxytQ%3D\u0026sid=812dcc77-0bd0-43b1-a5f1-b25750382959\u0026ts=1766395798"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=dAXmxloSScjS%2FZ9EIT1C%2B2SBB2h86QXaixpacFWxytQ%3D&sid=812dcc77-0bd0-43b1-a5f1-b25750382959&ts=1766395798"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 3.33.249.164:443 · api.tsed.dev
2025-12-21 01:59
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://raw.githubusercontent.com https://avatars.githubusercontent.com;media-src 'self';connect-src 'self' https://* wss://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Sun, 21 Dec 2025 01:59:35 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=%2BX7Juj%2BvJhEk%2BFBK4O4vLjZj%2Br4EMy4gqSUbNl2UF7Q%3D\u0026sid=812dcc77-0bd0-43b1-a5f1-b25750382959\u0026ts=1766282375"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=%2BX7Juj%2BvJhEk%2BFBK4O4vLjZj%2Br4EMy4gqSUbNl2UF7Q%3D&sid=812dcc77-0bd0-43b1-a5f1-b25750382959&ts=1766282375"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 52.223.53.203:80 · api.tsed.dev
2025-12-20 08:48
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://raw.githubusercontent.com https://avatars.githubusercontent.com;media-src 'self';connect-src 'self' https://* wss://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Sat, 20 Dec 2025 08:48:43 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=XqA5kU9NmxiZS2wOm2DEWiH0USKpHvmMhPZFdGcrbqg%3D\u0026sid=812dcc77-0bd0-43b1-a5f1-b25750382959\u0026ts=1766220523"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=XqA5kU9NmxiZS2wOm2DEWiH0USKpHvmMhPZFdGcrbqg%3D&sid=812dcc77-0bd0-43b1-a5f1-b25750382959&ts=1766220523"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin