Heroku
tcp/443 tcp/80
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Open service 99.83.217.1:80 · test.discovery.friendsta.tech
2026-01-09 19:51
HTTP/1.1 302 Found
Content-Length: 60
Content-Type: text/plain; charset=utf-8
Date: Fri, 09 Jan 2026 19:52:42 GMT
Location: https://test.discovery.friendsta.tech/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=xXWmqgg6bpITwstxAriOUiaIAIteMClNZ6zdbf9H6hI%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767988362"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=xXWmqgg6bpITwstxAriOUiaIAIteMClNZ6zdbf9H6hI%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767988362"
Server: Heroku
Set-Cookie: session=e30=; path=/; httponly
Set-Cookie: session.sig=EEWhvisvpGg_KlIxBKBiseN_FaI; path=/; httponly
Vary: Accept
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Found. Redirecting to https://test.discovery.friendsta.tech/
Open service 99.83.217.1:443 · test.discovery.friendsta.tech
2026-01-09 07:41
HTTP/1.1 200 OK
Content-Length: 629
Content-Type: text/html; charset=utf-8
Date: Fri, 09 Jan 2026 07:41:02 GMT
Etag: W/"275-kBblbp80mSHBMVF80wVmFVPfXgA"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=4qll%2FChAf6ntm9GWghSQzrFQQq%2BouqUpS2vfEbMUn8M%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767944462"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=4qll%2FChAf6ntm9GWghSQzrFQQq%2BouqUpS2vfEbMUn8M%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767944462"
Server: Heroku
Set-Cookie: session=e30=; path=/; secure; httponly
Set-Cookie: session.sig=EEWhvisvpGg_KlIxBKBiseN_FaI; path=/; secure; httponly
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Page title: Oppdagelsesplattform
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8" />
<link
rel="icon"
type="image/x-icon"
sizes="32x32"
href="/favicon-32x32.ico"
/>
<link
rel="icon"
type="image/x-icon"
sizes="16x16"
href="/favicon-16x16.ico"
/>
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
<title>Oppdagelsesplattform</title>
<script type="module" crossorigin src="/assets/index-Cup1Ns4i.js"></script>
<link rel="stylesheet" crossorigin href="/assets/index-Cx729gQn.css">
</head>
<body>
<div id="root"></div>
</body>
</html>
Open service 99.83.217.1:80 · test.discovery.friendsta.tech
2026-01-02 22:04
HTTP/1.1 302 Found
Content-Length: 60
Content-Type: text/plain; charset=utf-8
Date: Fri, 02 Jan 2026 22:04:38 GMT
Location: https://test.discovery.friendsta.tech/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=CZoF8BoJgtrEAmtSnptuEvwIi9EkAi0pUyA51TRuXZg%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767391478"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=CZoF8BoJgtrEAmtSnptuEvwIi9EkAi0pUyA51TRuXZg%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767391478"
Server: Heroku
Set-Cookie: session=e30=; path=/; httponly
Set-Cookie: session.sig=EEWhvisvpGg_KlIxBKBiseN_FaI; path=/; httponly
Vary: Accept
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Found. Redirecting to https://test.discovery.friendsta.tech/
Open service 99.83.217.1:443 · test.discovery.friendsta.tech
2026-01-02 05:58
HTTP/1.1 200 OK
Content-Length: 629
Content-Type: text/html; charset=utf-8
Date: Fri, 02 Jan 2026 05:58:04 GMT
Etag: W/"275-kBblbp80mSHBMVF80wVmFVPfXgA"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=N%2BocxLNzP3n2KrdTMihuR%2Fuf1hSOvRjF8BZG1d%2FgUsc%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767333484"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=N%2BocxLNzP3n2KrdTMihuR%2Fuf1hSOvRjF8BZG1d%2FgUsc%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767333484"
Server: Heroku
Set-Cookie: session=e30=; path=/; secure; httponly
Set-Cookie: session.sig=EEWhvisvpGg_KlIxBKBiseN_FaI; path=/; secure; httponly
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Page title: Oppdagelsesplattform
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8" />
<link
rel="icon"
type="image/x-icon"
sizes="32x32"
href="/favicon-32x32.ico"
/>
<link
rel="icon"
type="image/x-icon"
sizes="16x16"
href="/favicon-16x16.ico"
/>
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
<title>Oppdagelsesplattform</title>
<script type="module" crossorigin src="/assets/index-Cup1Ns4i.js"></script>
<link rel="stylesheet" crossorigin href="/assets/index-Cx729gQn.css">
</head>
<body>
<div id="root"></div>
</body>
</html>
Open service 99.83.217.1:80 · test.discovery.friendsta.tech
2025-12-23 07:12
HTTP/1.1 302 Found
Content-Length: 60
Content-Type: text/plain; charset=utf-8
Date: Tue, 23 Dec 2025 07:12:42 GMT
Location: https://test.discovery.friendsta.tech/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=7agQq6P0nvs6rCz5QOgb8oWSOWMGSmQvQQzWjj8BpIA%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766473962"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=7agQq6P0nvs6rCz5QOgb8oWSOWMGSmQvQQzWjj8BpIA%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766473962"
Server: Heroku
Set-Cookie: session=e30=; path=/; httponly
Set-Cookie: session.sig=EEWhvisvpGg_KlIxBKBiseN_FaI; path=/; httponly
Vary: Accept
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Found. Redirecting to https://test.discovery.friendsta.tech/
Open service 99.83.217.1:443 · test.discovery.friendsta.tech
2025-12-22 21:10
HTTP/1.1 200 OK
Content-Length: 629
Content-Type: text/html; charset=utf-8
Date: Mon, 22 Dec 2025 21:10:34 GMT
Etag: W/"275-kBblbp80mSHBMVF80wVmFVPfXgA"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=hE%2FjKXiunaaqOEH4txl9JDDH%2BglSnbxKrkUm0lNn2IM%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766437834"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=hE%2FjKXiunaaqOEH4txl9JDDH%2BglSnbxKrkUm0lNn2IM%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766437834"
Server: Heroku
Set-Cookie: session=e30=; path=/; secure; httponly
Set-Cookie: session.sig=EEWhvisvpGg_KlIxBKBiseN_FaI; path=/; secure; httponly
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Page title: Oppdagelsesplattform
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8" />
<link
rel="icon"
type="image/x-icon"
sizes="32x32"
href="/favicon-32x32.ico"
/>
<link
rel="icon"
type="image/x-icon"
sizes="16x16"
href="/favicon-16x16.ico"
/>
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
<title>Oppdagelsesplattform</title>
<script type="module" crossorigin src="/assets/index-Cup1Ns4i.js"></script>
<link rel="stylesheet" crossorigin href="/assets/index-Cx729gQn.css">
</head>
<body>
<div id="root"></div>
</body>
</html>
Open service 99.83.217.1:443 · test.discovery.friendsta.tech
2025-12-21 00:23
HTTP/1.1 200 OK
Content-Length: 629
Content-Type: text/html; charset=utf-8
Date: Sun, 21 Dec 2025 00:23:14 GMT
Etag: W/"275-kBblbp80mSHBMVF80wVmFVPfXgA"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=KshjhyBMOJ5eVuv0tubz7FzYCZR0XlheXSroQu%2Bh5Xs%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766276594"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=KshjhyBMOJ5eVuv0tubz7FzYCZR0XlheXSroQu%2Bh5Xs%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766276594"
Server: Heroku
Set-Cookie: session=e30=; path=/; secure; httponly
Set-Cookie: session.sig=EEWhvisvpGg_KlIxBKBiseN_FaI; path=/; secure; httponly
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Page title: Oppdagelsesplattform
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8" />
<link
rel="icon"
type="image/x-icon"
sizes="32x32"
href="/favicon-32x32.ico"
/>
<link
rel="icon"
type="image/x-icon"
sizes="16x16"
href="/favicon-16x16.ico"
/>
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
<title>Oppdagelsesplattform</title>
<script type="module" crossorigin src="/assets/index-Cup1Ns4i.js"></script>
<link rel="stylesheet" crossorigin href="/assets/index-Cx729gQn.css">
</head>
<body>
<div id="root"></div>
</body>
</html>
Open service 99.83.217.1:80 · test.discovery.friendsta.tech
2025-12-20 23:58
HTTP/1.1 302 Found
Content-Length: 60
Content-Type: text/plain; charset=utf-8
Date: Sat, 20 Dec 2025 23:58:44 GMT
Location: https://test.discovery.friendsta.tech/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=wOv4D515%2BsLHLK%2F%2FGlBt2qGuh9AL9%2BMqC8Z66KdXtcI%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766275124"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=wOv4D515%2BsLHLK%2F%2FGlBt2qGuh9AL9%2BMqC8Z66KdXtcI%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766275124"
Server: Heroku
Set-Cookie: session=e30=; path=/; httponly
Set-Cookie: session.sig=EEWhvisvpGg_KlIxBKBiseN_FaI; path=/; httponly
Vary: Accept
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Found. Redirecting to https://test.discovery.friendsta.tech/