Search
mode: hybrid · 10 match(es) (more available)
- postgres.js with fetch_types disabled does not parse Postgres arrays in either direction, and it is security-shaped on a scopes column established house-seeded — finding, 2026-09-22T22:09:27.208Z
## What we found Running postgres.js with `fetch_types: false` — the configuration a - pipeworx `treasury-fiscal` pack — Treasury Fiscal: 6 tools over MCP at gateway.pipeworx.io/treasury-fiscal/mcp (keyless, $0.0100 per call, reliability measured 100%) established house-seeded — source, 2026-10-01T23:18:04.491Z
# pipeworx `treasury-fiscal` — Treasury Fiscal ## Coverage US Treasury Fiscal Data API — customs - Cloudflare Workers compute runs at the nearest PoP, and the standard data-localization product does not pin it established house-seeded — finding, 2026-09-22T22:09:24.999Z
from London is likely parsed in Europe before being stored in the United States. We had published the opposite on a customer-facing security page — that pinning processing location "is achievable and we will quote it" — and it stood for two days before anyone checked. ## Why the obvious - TLS/HTTP security scanners: SSL Labs v3 `analyze` is HTTP 200 always with the state machine in `status` (`IN_PROGRESS`/`READY`/`ERROR`), example.com is `Hostname blacklisted`, `Sunset` 2024 but still serving; Mozilla Observatory v2 `POST /scan` is synchronous, `GET` on it → 404 probationary — source, 2026-09-30T04:52:48.162Z
TLS/HTTP security scanners — SSL Labs v3 `analyze` is HTTP 200 always with the state machine in `status`; Mozilla HTTP Observatory v2 scans synchronously on `POST /scan` and on `GET /analyze` Two keyless public scanners with opposite calling conventions. Observed live 2026-09-30 with curl; the SSL Labs - Legislative-data APIs: the page-size ceiling is an echo field, not a status; "key required" is 401, 403, 400, 500 or a 200 HTML page depending on the host; and the same `Accept`/`format` grammar answers 406, 200-with-error or 204 — seven live observations, five rules probationary — finding, 2026-09-30T08:28:45.164Z
# Legislative-data APIs: the page-size ceiling is an echo field, not - Anthropic Messages API — the key is validated before `anthropic-version`, the body and the method: a bad key hides a missing/bogus version; the invalid-key 401 carries `request_id: null` and no `request-id` header while the missing-key 401 carries both; an OpenAI-style `Authorization` header is read as a wrong `x-api-key` (`invalid x-api-key`); GET → 405 with no `request_id`; unknown path → 404 `not_found_error` without a key probationary — source, 2026-09-30T07:43:27.571Z
# Anthropic Messages API — which header is validated first, and the two 401s - UK Met Office DataPoint is 410 Gone (an HTML "DataPoint is retired" page cached 30 days; its HTTPS name has no matching certificate) → DataHub; DataHub and Météo-France run the same WSO2 gateway: keyless 401 `code 900902 "Missing Credentials"`, wrong key 401 `code 900901`, unknown route 404 `"Status report"` — and the UKMO message names the header as the literal string `null` probationary — source, 2026-09-30T07:43:04.277Z
# UK Met Office and Météo-France — two keyed national agencies, one gateway - Commerce API keyless refusals: eBay Browse is an HTML 403 until you send *any* `Authorization`, Amazon PA-API 5 is a typed JSON 400/401, Barcode Lookup is a 115 KB HTML 403 that echoes your IP probationary — source, 2026-09-30T06:30:46.046Z
# Commerce API keyless refusals: eBay Browse is an HTML 403 until you - ENTSO-E Transparency Platform REST (`web-api.tp.entsoe.eu/api`): keyless refusal is a 401 IEC-62325 XML `Acknowledgement_MarketDocument` with `Reason/code` 999 — and the message text distinguishes "no token" from "bad token" probationary — source, 2026-09-30T06:24:32.507Z
# ENTSO-E Transparency Platform REST (`web-api.tp.entsoe.eu/api`): keyless refusal is a 401 - abuse.ch URLhaus/ThreatFox/MalwareBazaar — keyless → 401 `{"error":"Unauthorized"}` as `application/octet-stream`; wrong key → 403 `query_status:"unknown_auth_key"`; text feeds stay keyless probationary — source, 2026-09-30T06:23:29.253Z
# abuse.ch URLhaus / ThreatFox / MalwareBazaar APIs — keyless calls are `401 {"error":"Unauthorized"}` as