Heroku
tcp/443 tcp/80
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa33f7968935d18fad1935c16989860cae3847b88ef
GraphQL introspection enabled at /graphql Types: 142 (by kind: ENUM: 29, INPUT_OBJECT: 7, INTERFACE: 1, OBJECT: 98, SCALAR: 7) Operations: - Query: RootQueryType | fields: eventsForCharityId, listGiftsForUser, listPayrollForCompany, me, parseLocation - Mutation: RootMutationType | fields: assignUserRole, editMatch, editPurchaseComment, setEmailPrivate, setNotificationPrefs Directives: include, skip (total: 2)
Open service 15.197.152.254:80 · dev-api.cauze.com
2026-01-11 03:07
HTTP/1.1 301 Moved Permanently
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 0
Date: Sun, 11 Jan 2026 03:08:56 GMT
Location: https://ancient-shelf-15155.herokuapp.com/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=Uc8uAtOcybl5FKNP1GPug%2B4H6oLngh2iwtm%2F5RxFG5s%3D\u0026sid=67ff5de4-ad2b-4112-9289-cf96be89efed\u0026ts=1768100936"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=Uc8uAtOcybl5FKNP1GPug%2B4H6oLngh2iwtm%2F5RxFG5s%3D&sid=67ff5de4-ad2b-4112-9289-cf96be89efed&ts=1768100936"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
Open service 13.248.131.213:443 · dev-api.cauze.com
2026-01-11 03:07
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: null
Access-Control-Expose-Headers:
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 21
Content-Type: application/json; charset=utf-8
Cross-Origin-Window-Policy: deny
Date: Sun, 11 Jan 2026 03:07:54 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=sNpqwx4qG8T8NU5fsWQmRc%2BnwdiLS5lat1D2nONNDY8%3D\u0026sid=67ff5de4-ad2b-4112-9289-cf96be89efed\u0026ts=1768100874"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=sNpqwx4qG8T8NU5fsWQmRc%2BnwdiLS5lat1D2nONNDY8%3D&sid=67ff5de4-ad2b-4112-9289-cf96be89efed&ts=1768100874"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: f12cb24f-2af5-8c52-31c0-962d59760f4b
X-Xss-Protection: 1; mode=block
Connection: close
{"health-check":"UP"}
Open service 3.33.161.45:80 · dev-api.cauze.com
2026-01-11 03:07
HTTP/1.1 301 Moved Permanently
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 0
Date: Sun, 11 Jan 2026 03:08:56 GMT
Location: https://ancient-shelf-15155.herokuapp.com/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=Uc8uAtOcybl5FKNP1GPug%2B4H6oLngh2iwtm%2F5RxFG5s%3D\u0026sid=67ff5de4-ad2b-4112-9289-cf96be89efed\u0026ts=1768100936"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=Uc8uAtOcybl5FKNP1GPug%2B4H6oLngh2iwtm%2F5RxFG5s%3D&sid=67ff5de4-ad2b-4112-9289-cf96be89efed&ts=1768100936"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
Open service 35.71.150.51:443 · dev-api.cauze.com
2026-01-11 03:07
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: null
Access-Control-Expose-Headers:
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 21
Content-Type: application/json; charset=utf-8
Cross-Origin-Window-Policy: deny
Date: Sun, 11 Jan 2026 03:07:54 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=sNpqwx4qG8T8NU5fsWQmRc%2BnwdiLS5lat1D2nONNDY8%3D\u0026sid=67ff5de4-ad2b-4112-9289-cf96be89efed\u0026ts=1768100874"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=sNpqwx4qG8T8NU5fsWQmRc%2BnwdiLS5lat1D2nONNDY8%3D&sid=67ff5de4-ad2b-4112-9289-cf96be89efed&ts=1768100874"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: df65e318-2523-31ef-37ff-856d4edbb164
X-Xss-Protection: 1; mode=block
Connection: close
{"health-check":"UP"}
Open service 35.71.150.51:80 · dev-api.cauze.com
2026-01-11 03:07
HTTP/1.1 301 Moved Permanently
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 0
Date: Sun, 11 Jan 2026 03:08:55 GMT
Location: https://ancient-shelf-15155.herokuapp.com/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=w3jY2eYVT0zStv%2FZ5ySpPTxfeKQyQ4%2BxYwfHzqJlGXU%3D\u0026sid=67ff5de4-ad2b-4112-9289-cf96be89efed\u0026ts=1768100935"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=w3jY2eYVT0zStv%2FZ5ySpPTxfeKQyQ4%2BxYwfHzqJlGXU%3D&sid=67ff5de4-ad2b-4112-9289-cf96be89efed&ts=1768100935"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
Open service 13.248.131.213:80 · dev-api.cauze.com
2026-01-11 03:07
HTTP/1.1 301 Moved Permanently
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 0
Date: Sun, 11 Jan 2026 03:08:55 GMT
Location: https://ancient-shelf-15155.herokuapp.com/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=w3jY2eYVT0zStv%2FZ5ySpPTxfeKQyQ4%2BxYwfHzqJlGXU%3D\u0026sid=67ff5de4-ad2b-4112-9289-cf96be89efed\u0026ts=1768100935"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=w3jY2eYVT0zStv%2FZ5ySpPTxfeKQyQ4%2BxYwfHzqJlGXU%3D&sid=67ff5de4-ad2b-4112-9289-cf96be89efed&ts=1768100935"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
Open service 15.197.152.254:443 · dev-api.cauze.com
2026-01-11 03:07
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: null
Access-Control-Expose-Headers:
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 21
Content-Type: application/json; charset=utf-8
Cross-Origin-Window-Policy: deny
Date: Sun, 11 Jan 2026 03:07:54 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=sNpqwx4qG8T8NU5fsWQmRc%2BnwdiLS5lat1D2nONNDY8%3D\u0026sid=67ff5de4-ad2b-4112-9289-cf96be89efed\u0026ts=1768100874"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=sNpqwx4qG8T8NU5fsWQmRc%2BnwdiLS5lat1D2nONNDY8%3D&sid=67ff5de4-ad2b-4112-9289-cf96be89efed&ts=1768100874"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: eac94a48-48cf-78fb-bb44-70c6f24e9677
X-Xss-Protection: 1; mode=block
Connection: close
{"health-check":"UP"}
Open service 3.33.161.45:443 · dev-api.cauze.com
2026-01-11 03:07
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: null
Access-Control-Expose-Headers:
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 21
Content-Type: application/json; charset=utf-8
Cross-Origin-Window-Policy: deny
Date: Sun, 11 Jan 2026 03:07:54 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=sNpqwx4qG8T8NU5fsWQmRc%2BnwdiLS5lat1D2nONNDY8%3D\u0026sid=67ff5de4-ad2b-4112-9289-cf96be89efed\u0026ts=1768100874"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=sNpqwx4qG8T8NU5fsWQmRc%2BnwdiLS5lat1D2nONNDY8%3D&sid=67ff5de4-ad2b-4112-9289-cf96be89efed&ts=1768100874"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: cd915698-b916-1c40-adff-7bd26f927ea0
X-Xss-Protection: 1; mode=block
Connection: close
{"health-check":"UP"}
Open service 3.33.161.45:443 · dev-api.cauze.com
2026-01-09 09:42
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: null
Access-Control-Expose-Headers:
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 21
Content-Type: application/json; charset=utf-8
Cross-Origin-Window-Policy: deny
Date: Fri, 09 Jan 2026 09:42:44 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=dhLgYvYR%2BWxrfv5RT2lOQPv8nXbanYTMei7%2B2hxt68E%3D\u0026sid=67ff5de4-ad2b-4112-9289-cf96be89efed\u0026ts=1767951765"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=dhLgYvYR%2BWxrfv5RT2lOQPv8nXbanYTMei7%2B2hxt68E%3D&sid=67ff5de4-ad2b-4112-9289-cf96be89efed&ts=1767951765"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: bf5d97b5-15aa-de66-6693-86cb1c2d5d6f
X-Xss-Protection: 1; mode=block
Connection: close
{"health-check":"UP"}
Open service 3.33.161.45:443 · dev-api.cauze.com
2026-01-02 07:39
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: null
Access-Control-Expose-Headers:
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 21
Content-Type: application/json; charset=utf-8
Cross-Origin-Window-Policy: deny
Date: Fri, 02 Jan 2026 07:39:22 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=PWxPH6P6DJW60USCPhnhEbtlaYnkIXouVKy9VZ%2F%2BeM4%3D\u0026sid=67ff5de4-ad2b-4112-9289-cf96be89efed\u0026ts=1767339562"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=PWxPH6P6DJW60USCPhnhEbtlaYnkIXouVKy9VZ%2F%2BeM4%3D&sid=67ff5de4-ad2b-4112-9289-cf96be89efed&ts=1767339562"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 496d89ce-261d-6870-76f7-e0a9e54c4d50
X-Xss-Protection: 1; mode=block
Connection: close
{"health-check":"UP"}
Open service 3.33.161.45:443 · dev-api.cauze.com
2025-12-23 03:52
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: null
Access-Control-Expose-Headers:
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 21
Content-Type: application/json; charset=utf-8
Cross-Origin-Window-Policy: deny
Date: Tue, 23 Dec 2025 03:52:03 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=6%2FsYTXlGqHc9ickKUZkb8YXInqA9%2Be7Au1zgjT1k7VM%3D\u0026sid=67ff5de4-ad2b-4112-9289-cf96be89efed\u0026ts=1766461923"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=6%2FsYTXlGqHc9ickKUZkb8YXInqA9%2Be7Au1zgjT1k7VM%3D&sid=67ff5de4-ad2b-4112-9289-cf96be89efed&ts=1766461923"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 33b7d9d4-78fc-6650-3c14-fc518f5dc357
X-Xss-Protection: 1; mode=block
Connection: close
{"health-check":"UP"}
Open service 3.33.161.45:443 · dev-api.cauze.com
2025-12-21 01:31
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: null
Access-Control-Expose-Headers:
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 21
Content-Type: application/json; charset=utf-8
Cross-Origin-Window-Policy: deny
Date: Sun, 21 Dec 2025 01:31:23 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=YUwgmjoK8U2R63TvlbqcA4glSV52wFzO6NLEylPYIhM%3D\u0026sid=67ff5de4-ad2b-4112-9289-cf96be89efed\u0026ts=1766280684"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=YUwgmjoK8U2R63TvlbqcA4glSV52wFzO6NLEylPYIhM%3D&sid=67ff5de4-ad2b-4112-9289-cf96be89efed&ts=1766280684"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: a03ab613-154a-a6a6-b697-540df0a746be
X-Xss-Protection: 1; mode=block
Connection: close
{"health-check":"UP"}