Heroku
tcp/443 tcp/80
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3cf17fbff052b96cdc3930da844060f6362f0638b
GraphQL introspection enabled at /graphql Types: 526 (by kind: ENUM: 137, INPUT_OBJECT: 146, OBJECT: 230, SCALAR: 10, UNION: 3) Operations: - Query: Query | fields: agencies, amenities, amenity, availability, availableRooms - Mutation: Mutation | fields: addAADETransactionOrInvoice, addAgency, addAmenity, addCancellationPolicy, addChat Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa36dc01cf8e0a3aa1c8fe9f6c34631b0c2f659789e
GraphQL introspection enabled at /graphql Types: 522 (by kind: ENUM: 137, INPUT_OBJECT: 144, OBJECT: 228, SCALAR: 10, UNION: 3) Operations: - Query: Query | fields: agencies, amenities, amenity, availability, availableRooms - Mutation: Mutation | fields: addAADETransactionOrInvoice, addAgency, addAmenity, addCancellationPolicy, addChat Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3cf17fbff052b96cdc3930da844060f6362f0638b
GraphQL introspection enabled at /graphql Types: 526 (by kind: ENUM: 137, INPUT_OBJECT: 146, OBJECT: 230, SCALAR: 10, UNION: 3) Operations: - Query: Query | fields: agencies, amenities, amenity, availability, availableRooms - Mutation: Mutation | fields: addAADETransactionOrInvoice, addAgency, addAmenity, addCancellationPolicy, addChat Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa36dc01cf8e0a3aa1c8fe9f6c34631b0c2f659789e
GraphQL introspection enabled at /graphql Types: 522 (by kind: ENUM: 137, INPUT_OBJECT: 144, OBJECT: 228, SCALAR: 10, UNION: 3) Operations: - Query: Query | fields: agencies, amenities, amenity, availability, availableRooms - Mutation: Mutation | fields: addAADETransactionOrInvoice, addAgency, addAmenity, addCancellationPolicy, addChat Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Open service 15.197.129.158:80 · dev.api.roomismo.com
2026-01-09 08:24
HTTP/1.1 401 Unauthorized
Access-Control-Expose-Headers: force-refresh
Content-Length: 59
Content-Type: application/json; charset=utf-8
Date: Fri, 09 Jan 2026 08:25:18 GMT
Etag: W/"3b-vNssrMTPDtj5WhN5ckhp7/gS0WI"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=zYeFQ%2B4VZS8yYWF7y7ITWKfQlMCAbpDYQZQ1LsIVduE%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767947118"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=zYeFQ%2B4VZS8yYWF7y7ITWKfQlMCAbpDYQZQ1LsIVduE%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767947118"
Server: Heroku
Vary: Origin, Accept-Encoding
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
{"errors":[{"message":"apikeyVerification.appidRequired"}]}
Open service 76.223.11.49:443 · dev.api.roomismo.com
2026-01-09 05:39
HTTP/1.1 401 Unauthorized
Access-Control-Expose-Headers: force-refresh
Content-Length: 59
Content-Type: application/json; charset=utf-8
Date: Fri, 09 Jan 2026 05:39:47 GMT
Etag: W/"3b-vNssrMTPDtj5WhN5ckhp7/gS0WI"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=e10hFgBIPUlwVVjt0b0f8SnS%2BYUJIqYWuKWSW7DDlyA%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767937187"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=e10hFgBIPUlwVVjt0b0f8SnS%2BYUJIqYWuKWSW7DDlyA%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767937187"
Server: Heroku
Vary: Origin, Accept-Encoding
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
{"errors":[{"message":"apikeyVerification.appidRequired"}]}
Open service 15.197.129.158:80 · dev.api.roomismo.com
2026-01-02 10:36
HTTP/1.1 401 Unauthorized
Access-Control-Expose-Headers: force-refresh
Content-Length: 59
Content-Type: application/json; charset=utf-8
Date: Fri, 02 Jan 2026 10:36:39 GMT
Etag: W/"3b-vNssrMTPDtj5WhN5ckhp7/gS0WI"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=GrFXCoSEENB4l%2BfyEZhL6vy8y7PQLTAaiCHQ%2FETEivs%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767350199"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=GrFXCoSEENB4l%2BfyEZhL6vy8y7PQLTAaiCHQ%2FETEivs%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767350199"
Server: Heroku
Vary: Origin, Accept-Encoding
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
{"errors":[{"message":"apikeyVerification.appidRequired"}]}
Open service 76.223.11.49:443 · dev.api.roomismo.com
2026-01-02 04:56
HTTP/1.1 401 Unauthorized
Access-Control-Expose-Headers: force-refresh
Content-Length: 59
Content-Type: application/json; charset=utf-8
Date: Fri, 02 Jan 2026 04:56:43 GMT
Etag: W/"3b-vNssrMTPDtj5WhN5ckhp7/gS0WI"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=rVfGcvimwZYvmMTpLWe3%2BbeqrDIptwGoUok0VizN4DU%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767329803"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=rVfGcvimwZYvmMTpLWe3%2BbeqrDIptwGoUok0VizN4DU%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767329803"
Server: Heroku
Vary: Origin, Accept-Encoding
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
{"errors":[{"message":"apikeyVerification.appidRequired"}]}
Open service 76.223.11.49:443 · dev.api.roomismo.com
2025-12-22 17:12
HTTP/1.1 401 Unauthorized
Access-Control-Expose-Headers: force-refresh
Content-Length: 59
Content-Type: application/json; charset=utf-8
Date: Mon, 22 Dec 2025 17:12:05 GMT
Etag: W/"3b-vNssrMTPDtj5WhN5ckhp7/gS0WI"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=qlsMYVB2qhwIsbhPcZbshSSzTvZjJgTiRtY0J14KD%2Fs%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766423525"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=qlsMYVB2qhwIsbhPcZbshSSzTvZjJgTiRtY0J14KD%2Fs%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766423525"
Server: Heroku
Vary: Origin, Accept-Encoding
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
{"errors":[{"message":"apikeyVerification.appidRequired"}]}
Open service 15.197.129.158:80 · dev.api.roomismo.com
2025-12-22 15:20
HTTP/1.1 401 Unauthorized
Access-Control-Expose-Headers: force-refresh
Content-Length: 59
Content-Type: application/json; charset=utf-8
Date: Mon, 22 Dec 2025 15:20:40 GMT
Etag: W/"3b-vNssrMTPDtj5WhN5ckhp7/gS0WI"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=xRBmBbf%2BOfVD%2FgHmpojzljKgAqYkuXOHGtp3fCYn0RE%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766416840"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=xRBmBbf%2BOfVD%2FgHmpojzljKgAqYkuXOHGtp3fCYn0RE%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766416840"
Server: Heroku
Vary: Origin, Accept-Encoding
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
{"errors":[{"message":"apikeyVerification.appidRequired"}]}
Open service 15.197.129.158:80 · dev.api.roomismo.com
2025-12-20 18:53
HTTP/1.1 401 Unauthorized
Access-Control-Expose-Headers: force-refresh
Content-Length: 59
Content-Type: application/json; charset=utf-8
Date: Sat, 20 Dec 2025 18:53:42 GMT
Etag: W/"3b-vNssrMTPDtj5WhN5ckhp7/gS0WI"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=bB7tUaP47xmwdM8vHY%2FLvfU7U%2BpmXIZmIT4SpU5dnQc%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766256822"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=bB7tUaP47xmwdM8vHY%2FLvfU7U%2BpmXIZmIT4SpU5dnQc%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766256822"
Server: Heroku
Vary: Origin, Accept-Encoding
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
{"errors":[{"message":"apikeyVerification.appidRequired"}]}
Open service 76.223.11.49:443 · dev.api.roomismo.com
2025-12-20 14:11
HTTP/1.1 401 Unauthorized
Access-Control-Expose-Headers: force-refresh
Content-Length: 59
Content-Type: application/json; charset=utf-8
Date: Sat, 20 Dec 2025 14:11:09 GMT
Etag: W/"3b-vNssrMTPDtj5WhN5ckhp7/gS0WI"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=EoQ2yVWgXN70o89ynrvBv%2Fm7%2BjSfVjOpJH6WqMOjXkk%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766239869"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=EoQ2yVWgXN70o89ynrvBv%2Fm7%2BjSfVjOpJH6WqMOjXkk%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766239869"
Server: Heroku
Vary: Origin, Accept-Encoding
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
{"errors":[{"message":"apikeyVerification.appidRequired"}]}