nginx 1.22.1
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d6571aeb47788bd0753afcfb6a7b51f14c1a94625c
GraphQL introspection enabled at /api/graphql Types: 474 (by kind: ENUM: 12, INPUT_OBJECT: 386, OBJECT: 65, SCALAR: 8, UNION: 3) Operations: - Query: Query | fields: account, accountGroup, accountGroups, accounts, accountsCount - Mutation: Mutation | fields: createAccount, createAccounts, deleteAccount, updateAccount, updateAccounts Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 0
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d62337d3d62337d3d62337d3d62337d3d62337d3d6
GraphQL introspection enabled at /api/graphql
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d67813b5f6abf3ede61e7618a125bd16dbdfcf74e7
GraphQL introspection enabled at /api/graphql Types: 468 (by kind: ENUM: 12, INPUT_OBJECT: 380, OBJECT: 65, SCALAR: 8, UNION: 3) Operations: - Query: Query | fields: account, accountGroup, accountGroups, accounts, accountsCount - Mutation: Mutation | fields: createAccount, createAccounts, deleteAccount, updateAccount, updateAccounts Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 0
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d6764762ebb2aa24a94cfaaebe8c562810569d4258
GraphQL introspection enabled at /api/graphql Types: 483 (by kind: ENUM: 12, INPUT_OBJECT: 394, OBJECT: 66, SCALAR: 8, UNION: 3) Operations: - Query: Query | fields: account, accountGroup, accountGroups, accounts, accountsCount - Mutation: Mutation | fields: createAccount, createAccounts, deleteAccount, updateAccount, updateAccounts Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 0
Open service 34.165.43.63:443 ยท main.milgo.io
2026-01-23 12:49
HTTP/1.1 302 Found Server: nginx/1.22.1 Date: Fri, 23 Jan 2026 12:49:26 GMT Content-Length: 0 Connection: close X-Powered-By: Express Vary: Origin Access-Control-Allow-Credentials: true Content-Security-Policy: default-src * 'unsafe-inline' 'unsafe-eval'; script-src * 'unsafe-inline' 'unsafe-eval'; connect-src * 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; frame-src *; style-src * 'unsafe-inline'; font-src: * 'unsafe-inline'; Permissions-Policy: interest-cohort=() X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff Referrer-Policy: no-referrer Cache-Control: no-cache, max-age=0 Location: /signin