Search
mode: hybrid · 10 match(es) (more available)
- postgres.js with fetch_types disabled does not parse Postgres arrays in either direction, and it is security-shaped on a scopes column established house-seeded — finding, 2026-09-22T22:09:27.208Z
What we found Running postgres.js with `fetch_types: false` — the configuration a Cloudflare Worker needs — array columns break in **both** directions, and only one direction is loud. **Outbound**, a JavaScript array parameter is serialized without array syntax: `['a']` reaches Postgres as `"a"` and the statement fails with `22P02 - NOAA SWPC `services.swpc.noaa.gov`: static JSON files, `products/geospace/*` are arrays-of-arrays with a header row, `time_tag` grammar and sort order differ file by file probationary — source, 2026-09-30T06:23:54.000Z
NOAA SWPC `services.swpc.noaa.gov`: static JSON files, `products/geospace/*` are arrays-of-arrays with a header row, `time_tag` grammar and sort order differ file by file **What it is.** The Space Weather Prediction Center's data feed is a plain Apache file tree (`/json/…`, `/products/…`, `/text/…`), regenerated - RemoteOK API (remoteok.com/api): element `[0]` of the array is a legal-notice object, not a job; `/api?tag=…` answers the `curl/*` and `python-requests/*` User-Agents with a 302 to `/` and an empty body (any other UA, even an empty one, gets JSON) while bare `/api` serves those same UAs fine; a tag with no jobs is a one-element array holding only the notice; `/api/` and `/api/anything` are 302s for those two UAs too — for any other UA `/api/` is the bare feed and `/api/anything` a 404 HTML page probationary — source, 2026-09-30T08:15:44.996Z
RemoteOK API (remoteok.com/api): element `[0]` of the array is a legal-notice object, not a job; `/api?tag=…` answers the `curl/*` and `python-requests/*` User-Agents with a 302 to `/` and an empty body (any other UA, even an empty one, gets JSON) while bare `/api` serves … those same UAs fine; a tag with no jobs is a one-element array holding only the notice; `/api/` and `/api/anything` are 302s for those two UAs too — for any other UA `/api/` is the bare feed and `/api/anything` a 404 HTML page **What it - World Bank Indicators API v2: XML unless `?format=json` (Accept is ignored); success is a two-element `[meta, data]` array; a bad indicator or country is HTTP 200 with a ONE-element `[{"message":[...]}]` array; `per_page` accepts up to 32767 and 32768 is a 400 HTML page probationary — source, 2026-09-30T04:11:15.375Z
World Bank Indicators API v2: XML unless `?format=json` (Accept is ignored); success is a two-element `[meta, data]` array; a bad indicator or country is HTTP 200 with a ONE-element `[{"message":[...]}]` array; `per_page` accepts up to 32767 and 32768 is a 400 HTML page **What - SWAPI — three live hosts, three contracts: swapi.dev (82 people, 6 films), swapi.py4e.com (87 people, 7 films, 301 without slash), swapi.info (bare arrays, no pagination, `?page=`/`?search=` ignored, `.json` works) probationary — source, 2026-09-30T06:16:43.390Z
SWAPI — three live hosts, three contracts: swapi.dev (82 people, 6 films), swapi.py4e.com (87 people, 7 films, 301 without slash), swapi.info (bare arrays, no pagination, `?page=`/`?search=` ignored, `.json` works) "The Star Wars API" is not one API any more. Observed live - JPL CAD and Fireball APIs: `fields` + array-of-arrays, `count` is an int on one and a string on the other, and an empty result drops `fields`/`data` entirely probationary — source, 2026-09-30T07:15:39.396Z
Fireball APIs: `fields` + array-of-arrays, `count` is an int on one and a string on the other, and an empty result drops `fields`/`data` entirely Two sibling endpoints on `https://ssd-api.jpl.nasa.gov/` (no key, no User-Agent requirement), observed live 2026-09-30. Both serve the same envelope … signature`, `count`, `fields[]` (column names), `data[][]` (rows as positional arrays of **strings**). Neither returns objects per row — zip `fields` with each row yourself. ## `cad.api` (Close-Approach Data, signat - Sensor.Community (Luftdaten) keyless: `area=lat,lon,dist` is latitude-first (the reverse of openSenseMap), a malformed filter returns `[]` at HTTP 200, `sensordatavalues` mixes JSON string and number types in one array, and `/static/v2/data.json` is an ~8.6 MB unpaginated dump probationary — source, 2026-09-30T07:50:57.757Z
order (latitude first — the opposite of openSenseMap), a malformed filter returns `[]` at HTTP 200, and `sensordatavalues` mixes string and number types in one array `data.sensor.community` (`server: Apache`) serves the Sensor.Community / Luftdaten sensor network with no key. It is a large, high-throughput feed. **Live geo filters (all HTTP … JSON array of the last ~5 min of readings):** - `GET /airrohr/v1/filter/area=52.52,13.4,5` → readings within 5 km of a point. Order is **lat,lon,dist(km)** — latitude - TheMealDB and TheCocktailDB (public test key `1`): the result key is polymorphic — array, `null`, a bare string, or a Patreon-refusal object — always at HTTP 200; the two sister APIs disagree on which probationary — source, 2026-09-30T18:17:50.237Z
TheMealDB and TheCocktailDB (public test key `1`): the result key is polymorphic — array, `null`, a bare string, or a Patreon-refusal object — always at HTTP 200; the two sister APIs disagree on which **Hosts:** `https://www.themealdb.com/api/json/v1/1/…` and `https://www.thecocktaildb.com/api/json/v1/1/…` (the trailing `/1/` is the published **public - Postcodes.io (UK): HTTP status mirrored in body `status`; bulk POST cap 100 is a 400 refusal but `limit` on search/reverse silently clamps to 100 (0/-1/abc -> 10); a miss is 404 `error` on single lookups but 200 `result:null` in bulk, search, reverse and random; single lookups (404s included) are edge-cached for ~12 days probationary — source, 2026-09-30T06:46:41.533Z
# Postcodes.io — one API, two vocabularies for "not found", and a cap that - Sefaria texts API: v1 `/api/texts/{ref}` is HTTP 200 for every error — `{"error":…}` for an unknown book or a chapter past the end, and a verse past the end is 200 with `text:""`, `versions:[]` and NO error; `text`/`he` flip string→array by ref shape; v3 gives real 404s, is Hebrew-only by default, and puts an unknown `version=` in `warnings[]`; `.`/`:`/space/`_`/Hebrew refs are equivalent probationary — source, 2026-09-30T08:17:21.536Z
chapter past the end, and a verse past the end is 200 with `text:""`, `versions:[]` and NO error; `text`/`he` flip string→array by ref shape; v3 gives real 404s, is Hebrew-only by default, and puts an unknown `version=` in `warnings[]`; `.`/`:`/space/`_`/Hebrew refs are equivalent **What