Heroku
tcp/443 tcp/80
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3503b70b19a3dd9b39eff3fd319cfa3fa26447418
GraphQL introspection enabled at /graphql Types: 76 (by kind: ENUM: 3, INPUT_OBJECT: 7, INTERFACE: 4, OBJECT: 46, SCALAR: 7, UNION: 9) Operations: - Query: Query | fields: checkEmail, checkNickname, item, items, searchMovies - Mutation: Mutation | fields: createItem, createManualMovieItem, createTypedMovieItem, deleteItem, updateItem Directives: catchAndReturnExpectedError, deprecated, include, isAdmin, isAdminOrThrow, isAuthenticated, isAuthenticatedOrThrow, isPartiallyAuthenticatedOrThrow, skip, specifiedBy (total: 11)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa37860f46f5898ff3d02d89ab46b94baae2ab11c8b
GraphQL introspection enabled at /graphql Types: 62 (by kind: ENUM: 2, INPUT_OBJECT: 2, INTERFACE: 4, OBJECT: 39, SCALAR: 8, UNION: 7) Operations: - Query: Query | fields: checkEmail, checkNickname, item, items, me - Mutation: Mutation | fields: createAdminUser, createItem, createUserWithAppleAuth, deleteItem, updateItem Directives: catchAndReturnExpectedError, deprecated, include, isAdmin, isAdminOrThrow, isAuthenticated, isAuthenticatedOrThrow, isPartiallyAuthenticatedOrThrow, skip, specifiedBy (total: 10)
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3503b70b19a3dd9b39eff3fd319cfa3fa26447418
GraphQL introspection enabled at /graphql Types: 76 (by kind: ENUM: 3, INPUT_OBJECT: 7, INTERFACE: 4, OBJECT: 46, SCALAR: 7, UNION: 9) Operations: - Query: Query | fields: checkEmail, checkNickname, item, items, searchMovies - Mutation: Mutation | fields: createItem, createManualMovieItem, createTypedMovieItem, deleteItem, updateItem Directives: catchAndReturnExpectedError, deprecated, include, isAdmin, isAdminOrThrow, isAuthenticated, isAuthenticatedOrThrow, isPartiallyAuthenticatedOrThrow, skip, specifiedBy (total: 11)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa37860f46f5898ff3d02d89ab46b94baae2ab11c8b
GraphQL introspection enabled at /graphql Types: 62 (by kind: ENUM: 2, INPUT_OBJECT: 2, INTERFACE: 4, OBJECT: 39, SCALAR: 8, UNION: 7) Operations: - Query: Query | fields: checkEmail, checkNickname, item, items, me - Mutation: Mutation | fields: createAdminUser, createItem, createUserWithAppleAuth, deleteItem, updateItem Directives: catchAndReturnExpectedError, deprecated, include, isAdmin, isAdminOrThrow, isAuthenticated, isAuthenticatedOrThrow, isPartiallyAuthenticatedOrThrow, skip, specifiedBy (total: 10)
Open service 35.71.179.82:80 · www.lifelist.dev
2026-01-09 20:39
HTTP/1.1 302 Found
Access-Control-Allow-Origin: *
Content-Length: 33
Content-Type: text/plain; charset=utf-8
Date: Fri, 09 Jan 2026 20:40:24 GMT
Location: /v1/graphql
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=iguY9o6%2BL8xe0K8ox91qBj72KlizCkg5aZQowlzO%2B58%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767991224"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=iguY9o6%2BL8xe0K8ox91qBj72KlizCkg5aZQowlzO%2B58%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767991224"
Server: Heroku
Vary: Accept, Accept-Encoding
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Found. Redirecting to /v1/graphql
Open service 35.71.179.82:443 · www.lifelist.dev
2026-01-09 12:35
HTTP/1.1 302 Found
Access-Control-Allow-Origin: *
Content-Length: 33
Content-Type: text/plain; charset=utf-8
Date: Fri, 09 Jan 2026 12:35:42 GMT
Location: /v1/graphql
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=6rBjGGiuIJxzO2q%2FDE4wj5N%2BBgwjoCd1LCUKDZp%2F5TU%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767962142"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=6rBjGGiuIJxzO2q%2FDE4wj5N%2BBgwjoCd1LCUKDZp%2F5TU%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767962142"
Server: Heroku
Vary: Accept, Accept-Encoding
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Found. Redirecting to /v1/graphql
Open service 35.71.179.82:80 · www.lifelist.dev
2026-01-02 17:03
HTTP/1.1 302 Found
Access-Control-Allow-Origin: *
Content-Length: 33
Content-Type: text/plain; charset=utf-8
Date: Fri, 02 Jan 2026 17:04:02 GMT
Location: /v1/graphql
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=xK0pgZQIYnHK4nxn0SiqwsjIOmpdnfIoAL6zaG4criY%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767373442"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=xK0pgZQIYnHK4nxn0SiqwsjIOmpdnfIoAL6zaG4criY%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767373442"
Server: Heroku
Vary: Accept, Accept-Encoding
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Found. Redirecting to /v1/graphql
Open service 35.71.179.82:443 · www.lifelist.dev
2026-01-02 02:03
HTTP/1.1 302 Found
Access-Control-Allow-Origin: *
Content-Length: 33
Content-Type: text/plain; charset=utf-8
Date: Fri, 02 Jan 2026 02:03:21 GMT
Location: /v1/graphql
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=fe6IDcySpuuF6yMXEPm3Xu5enLPiaYp%2FDmhd3z0PCAA%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767319401"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=fe6IDcySpuuF6yMXEPm3Xu5enLPiaYp%2FDmhd3z0PCAA%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767319401"
Server: Heroku
Vary: Accept, Accept-Encoding
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Found. Redirecting to /v1/graphql
Open service 35.71.179.82:443 · www.lifelist.dev
2025-12-30 12:10
HTTP/1.1 302 Found
Access-Control-Allow-Origin: *
Content-Length: 33
Content-Type: text/plain; charset=utf-8
Date: Tue, 30 Dec 2025 12:10:36 GMT
Location: /v1/graphql
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=ZYRHkVm8F3pPxzrPnghvf5DTgA7eUM7Ao6qZ58F1iSM%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767096636"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=ZYRHkVm8F3pPxzrPnghvf5DTgA7eUM7Ao6qZ58F1iSM%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767096636"
Server: Heroku
Vary: Accept, Accept-Encoding
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Found. Redirecting to /v1/graphql
Open service 35.71.179.82:80 · www.lifelist.dev
2025-12-23 01:56
HTTP/1.1 302 Found
Access-Control-Allow-Origin: *
Content-Length: 33
Content-Type: text/plain; charset=utf-8
Date: Tue, 23 Dec 2025 01:56:29 GMT
Location: /v1/graphql
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=mLt%2BBmBzRmP0Z7ebPDaM0CRqzVeIhlFceYHnVPEZOkA%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766454989"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=mLt%2BBmBzRmP0Z7ebPDaM0CRqzVeIhlFceYHnVPEZOkA%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766454989"
Server: Heroku
Vary: Accept, Accept-Encoding
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Found. Redirecting to /v1/graphql
Open service 35.71.179.82:443 · www.lifelist.dev
2025-12-22 06:36
HTTP/1.1 302 Found
Access-Control-Allow-Origin: *
Content-Length: 33
Content-Type: text/plain; charset=utf-8
Date: Mon, 22 Dec 2025 06:36:22 GMT
Location: /v1/graphql
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=KfC%2FvK%2FCr7Yg5bXF%2BzgEeW3jcbEZZZvnAnnTJMQh6N8%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766385382"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=KfC%2FvK%2FCr7Yg5bXF%2BzgEeW3jcbEZZZvnAnnTJMQh6N8%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766385382"
Server: Heroku
Vary: Accept, Accept-Encoding
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Found. Redirecting to /v1/graphql
Open service 35.71.179.82:443 · www.lifelist.dev
2025-12-20 18:07
HTTP/1.1 302 Found
Access-Control-Allow-Origin: *
Content-Length: 33
Content-Type: text/plain; charset=utf-8
Date: Sat, 20 Dec 2025 18:07:11 GMT
Location: /v1/graphql
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=SPF4HzEsLfcYx%2Fmz%2BJww3f%2FvAQNuvq1Px6emh3%2BXBL4%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766254031"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=SPF4HzEsLfcYx%2Fmz%2BJww3f%2FvAQNuvq1Px6emh3%2BXBL4%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766254031"
Server: Heroku
Vary: Accept, Accept-Encoding
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Found. Redirecting to /v1/graphql
Open service 35.71.179.82:80 · www.lifelist.dev
2025-12-20 14:43
HTTP/1.1 302 Found
Access-Control-Allow-Origin: *
Content-Length: 33
Content-Type: text/plain; charset=utf-8
Date: Sat, 20 Dec 2025 14:43:09 GMT
Location: /v1/graphql
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=Opb4FoJQuW%2FS5OLxQXvyKamal5xHZi2LzOpny0QYUjI%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766241789"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=Opb4FoJQuW%2FS5OLxQXvyKamal5xHZi2LzOpny0QYUjI%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766241789"
Server: Heroku
Vary: Accept, Accept-Encoding
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Found. Redirecting to /v1/graphql
Open service 35.71.179.82:443 · www.lifelist.dev
2025-12-19 02:52
HTTP/1.1 302 Found
Access-Control-Allow-Origin: *
Content-Length: 33
Content-Type: text/plain; charset=utf-8
Date: Fri, 19 Dec 2025 02:52:01 GMT
Location: /v1/graphql
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=8XOTiDhfEiIvdU8Mqs1YcY9cZSulORcilQuBL2lRvI0%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766112721"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=8XOTiDhfEiIvdU8Mqs1YcY9cZSulORcilQuBL2lRvI0%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766112721"
Server: Heroku
Vary: Accept, Accept-Encoding
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Found. Redirecting to /v1/graphql