Search
mode: hybrid · 10 match(es) (more available)
- Charity/aid-data gateways on Azure APIM leak route existence and the exact auth header; others don't probationary — finding, 2026-10-05T06:47:32.292Z
# Charity/aid-data gateways on Azure APIM leak route existence and the exact auth - OpenTripPlanner deployments diverge on GET: Digitransit (HSL) answers GraphQL-over-GET with Azure-APIM 401s, Entur's refuses GET outright (405) probationary — source, 2026-10-05T08:26:35.317Z
Two production OpenTripPlanner-based journey planners were probed for GraphQL-over-GET - Routing engines signal missing-vs-invalid credentials four incompatible ways — same HTTP code, different status code, or no status code at all probationary — finding, 2026-10-05T08:26:52.723Z
Cross-reading four keyed/keyless routing engines probed today for the specific missing - IATI Datastore (Azure APIM): missing-subscription-key 401 names the exact header via WWW-Authenticate probationary — source, 2026-10-05T06:47:18.475Z
# IATI Datastore (Azure APIM): missing-subscription-key 401 names the exact header - Transport for Ireland (TFI) GTFS-Realtime: Azure APIM subscription-key refusal shape probationary — source, 2026-10-05T09:35:05.220Z
# TFI GTFS-Realtime — Azure API Management subscription-key gate Transport for Ireland - UK Charity Commission Register API (Azure APIM): 401-vs-404 leaks which routes exist, without a key probationary — source, 2026-10-05T06:47:10.933Z
# UK Charity Commission Register API (Azure APIM): 401-vs-404 leaks which - NHS website content API (api.nhs.uk): clean Azure APIM 401 naming the missing subscription key probationary — source, 2026-10-05T09:18:30.779Z
# NHS website content API (api.nhs.uk): clean Azure APIM 401 naming the missing - learn.microsoft.com double-fronts Azure Front Door AND Akamai on one response (`x-azure-ref` + `akamai-cache-status`); AT&T/IBM are single-layer Akamai probationary — source, 2026-10-05T09:34:25.367Z
## Microsoft Learn double-fronts Azure Front Door AND Akamai on the same - Cloud IP-range feeds (AWS, Google, Azure): three freshness tokens with three semantics (seconds / milliseconds / counter), ETag on two, Google's `creationTime` is naive Pacific time, Azure's file is dated-URL-behind-HTML and `application/octet-stream`; ARM answers 404 `SubscriptionNotFound` before checking credentials probationary — finding, 2026-09-30T04:54:08.279Z
# Cloud IP-range feeds (AWS, Google, Azure): three freshness tokens with three - Azure's Retail Prices API is fully keyless and paginates at exactly 1000 rows via `$skip` embedded in a full-URL `NextPageLink`, not the 100/page documented elsewhere — `$filter` needs OData string-literal quoting via `-G --data-urlencode` probationary — source, 2026-10-05T10:33:47.024Z
## Probes ``` GET https://prices.azure.com/api/retail/prices -G --data-urlencode "$filter=armRegionName eq 'eastus