GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3579893ef77e809bd40f1c89b2ffa4099b3ffee05
GraphQL introspection enabled at /graphql Types: 282 (by kind: ENUM: 22, INPUT_OBJECT: 109, OBJECT: 135, SCALAR: 12, UNION: 4) Operations: - Query: Query | fields: reviewWorkflowsWorkflow, reviewWorkflowsWorkflowStage, reviewWorkflowsWorkflowStages_connection, reviewWorkflowsWorkflows, reviewWorkflowsWorkflows_connection - Mutation: Mutation | fields: createReviewWorkflowsWorkflow, createReviewWorkflowsWorkflowStage, deleteReviewWorkflowsWorkflow, updateReviewWorkflowsWorkflow, updateReviewWorkflowsWorkflowStage Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3924bbec4b2b0d788603728843e578d261b4f5b82
GraphQL introspection enabled at /graphql Types: 289 (by kind: ENUM: 25, INPUT_OBJECT: 111, OBJECT: 137, SCALAR: 12, UNION: 4) Operations: - Query: Query | fields: reviewWorkflowsWorkflow, reviewWorkflowsWorkflowStage, reviewWorkflowsWorkflowStages_connection, reviewWorkflowsWorkflows, reviewWorkflowsWorkflows_connection - Mutation: Mutation | fields: createReviewWorkflowsWorkflow, createReviewWorkflowsWorkflowStage, deleteReviewWorkflowsWorkflow, updateReviewWorkflowsWorkflow, updateReviewWorkflowsWorkflowStage Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa38d19eca422242528ce223824b15a8106482561a2
GraphQL introspection enabled at /graphql Types: 286 (by kind: ENUM: 25, INPUT_OBJECT: 110, OBJECT: 135, SCALAR: 12, UNION: 4) Operations: - Query: Query | fields: reviewWorkflowsWorkflow, reviewWorkflowsWorkflowStage, reviewWorkflowsWorkflowStages_connection, reviewWorkflowsWorkflows, reviewWorkflowsWorkflows_connection - Mutation: Mutation | fields: createReviewWorkflowsWorkflow, createReviewWorkflowsWorkflowStage, deleteReviewWorkflowsWorkflow, updateReviewWorkflowsWorkflow, updateReviewWorkflowsWorkflowStage Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3842dcd750d67a277e7563c4d38a78adb96947773
GraphQL introspection enabled at /graphql Types: 280 (by kind: ENUM: 25, INPUT_OBJECT: 108, OBJECT: 131, SCALAR: 12, UNION: 4) Operations: - Query: Query | fields: reviewWorkflowsWorkflow, reviewWorkflowsWorkflowStage, reviewWorkflowsWorkflowStages_connection, reviewWorkflowsWorkflows, reviewWorkflowsWorkflows_connection - Mutation: Mutation | fields: createReviewWorkflowsWorkflow, createReviewWorkflowsWorkflowStage, deleteReviewWorkflowsWorkflow, updateReviewWorkflowsWorkflow, updateReviewWorkflowsWorkflowStage Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa39e695906b0a3aef6022805ba0a35eba44ec70104
GraphQL introspection enabled at /graphql Types: 263 (by kind: ENUM: 25, INPUT_OBJECT: 100, OBJECT: 124, SCALAR: 11, UNION: 3) Operations: - Query: Query | fields: reviewWorkflowsWorkflow, reviewWorkflowsWorkflowStage, reviewWorkflowsWorkflowStages_connection, reviewWorkflowsWorkflows, reviewWorkflowsWorkflows_connection - Mutation: Mutation | fields: createReviewWorkflowsWorkflow, createReviewWorkflowsWorkflowStage, deleteReviewWorkflowsWorkflow, updateReviewWorkflowsWorkflow, updateReviewWorkflowsWorkflowStage Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Open service 142.250.185.147:443 · strapi-stage.restaurantweek.dev
2026-01-23 11:26
HTTP/1.1 302 Found content-security-policy: connect-src 'self' https:;img-src 'self' data: blob: https://cdn-stage.rclub.dev;media-src 'self' data: blob: https://cdn-stage.rclub.dev;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src 'self';script-src-attr 'none';style-src 'self' https: 'unsafe-inline' referrer-policy: no-referrer strict-transport-security: max-age=31536000; includeSubDomains x-content-type-options: nosniff x-dns-prefetch-control: off x-download-options: noopen x-frame-options: SAMEORIGIN x-permitted-cross-domain-policies: none vary: Origin access-control-allow-origin: access-control-allow-credentials: true location: https://strapi-stage.restaurantweek.dev/admin content-type: text/html; charset=utf-8 x-powered-by: Strapi <strapi.io> x-cloud-trace-context: ead1fa8a5efdbca0d99b815b1a4d231f date: Fri, 23 Jan 2026 11:26:37 GMT server: Google Frontend Content-Length: 121 Connection: close Redirecting to <a href="https://strapi-stage.restaurantweek.dev/admin">https://strapi-stage.restaurantweek.dev/admin</a>.
Open service 142.250.185.147:443 · strapi-stage.restaurantweek.dev
2026-01-09 12:31
HTTP/1.1 302 Found content-security-policy: connect-src 'self' https:;img-src 'self' data: blob: https://cdn-stage.rclub.dev;media-src 'self' data: blob: https://cdn-stage.rclub.dev;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src 'self';script-src-attr 'none';style-src 'self' https: 'unsafe-inline' referrer-policy: no-referrer strict-transport-security: max-age=31536000; includeSubDomains x-content-type-options: nosniff x-dns-prefetch-control: off x-download-options: noopen x-frame-options: SAMEORIGIN x-permitted-cross-domain-policies: none vary: Origin access-control-allow-origin: access-control-allow-credentials: true location: https://strapi-stage.restaurantweek.dev/admin content-type: text/html; charset=utf-8 x-powered-by: Strapi <strapi.io> x-cloud-trace-context: 81f4dd9f16dc99e60c9e0937b89a34aa date: Fri, 09 Jan 2026 12:32:00 GMT server: Google Frontend Content-Length: 121 Connection: close Redirecting to <a href="https://strapi-stage.restaurantweek.dev/admin">https://strapi-stage.restaurantweek.dev/admin</a>.
Open service 142.250.185.147:443 · strapi-stage.restaurantweek.dev
2026-01-02 15:28
HTTP/1.1 302 Found content-security-policy: connect-src 'self' https:;img-src 'self' data: blob: https://cdn-stage.rclub.dev;media-src 'self' data: blob: https://cdn-stage.rclub.dev;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src 'self';script-src-attr 'none';style-src 'self' https: 'unsafe-inline' referrer-policy: no-referrer strict-transport-security: max-age=31536000; includeSubDomains x-content-type-options: nosniff x-dns-prefetch-control: off x-download-options: noopen x-frame-options: SAMEORIGIN x-permitted-cross-domain-policies: none vary: Origin access-control-allow-origin: access-control-allow-credentials: true location: https://strapi-stage.restaurantweek.dev/admin content-type: text/html; charset=utf-8 x-powered-by: Strapi <strapi.io> x-cloud-trace-context: 0a7a4dc297d639a320c94a6fff245ba1 date: Fri, 02 Jan 2026 15:28:29 GMT server: Google Frontend Content-Length: 121 Connection: close Redirecting to <a href="https://strapi-stage.restaurantweek.dev/admin">https://strapi-stage.restaurantweek.dev/admin</a>.
Open service 142.250.185.147:443 · strapi-stage.restaurantweek.dev
2025-12-22 17:27
HTTP/1.1 302 Found content-security-policy: connect-src 'self' https:;img-src 'self' data: blob: https://cdn-stage.rclub.dev;media-src 'self' data: blob: https://cdn-stage.rclub.dev;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src 'self';script-src-attr 'none';style-src 'self' https: 'unsafe-inline' referrer-policy: no-referrer strict-transport-security: max-age=31536000; includeSubDomains x-content-type-options: nosniff x-dns-prefetch-control: off x-download-options: noopen x-frame-options: SAMEORIGIN x-permitted-cross-domain-policies: none vary: Origin access-control-allow-origin: access-control-allow-credentials: true location: https://strapi-stage.restaurantweek.dev/admin content-type: text/html; charset=utf-8 x-powered-by: Strapi <strapi.io> x-cloud-trace-context: 038bd024c69399a40ee58f22577d5935 date: Mon, 22 Dec 2025 17:27:31 GMT server: Google Frontend Content-Length: 121 Connection: close Redirecting to <a href="https://strapi-stage.restaurantweek.dev/admin">https://strapi-stage.restaurantweek.dev/admin</a>.