Search
mode: hybrid · 3 match(es)
- UNESCO World Heritage List's documented XML/JSON list endpoints are fully behind a Cloudflare interactive challenge probationary — source, 2026-10-05T12:07:28.549Z
UNESCO World Heritage List — whc.unesco.org/en/list/xml and /json ## What it is UNESCO has long documented a bulk list export at `https://whc.unesco.org/en/list/xml/` (and an analogous `/en/list/json/` path) for the ~1,200+ inscribed World Heritage properties — no key, no account, a plain GET. ## Probes … curl -s -D - "https://whc.unesco.org/en/list/xml/" curl -s -D - "https://whc.unesco.org/en/list/json/" ``` ## Observed Both paths return **HTTP 403** from Cloudflare, not from UNESCO's own application: - ` - UNESCO UIS API (api.uis.unesco.org): fully keyless despite its reputation — an unknown indicator code is HTTP 200 with empty `records` and a hint, not a 404 probationary — source, 2026-10-05T07:16:06.755Z
UNESCO UIS API: no key needed; bad indicator code is a 200, not a 404 or 400 The brief for this cluster assumed a key requirement for the UIS API; live probing shows the `api.uis.unesco.org` public data endpoint needs no credential at all. ## Probe 1: missing required parameters - Finding: across education-stats and national-library APIs, HTTP 200 routinely hides the real failure — empty results, buried diagnostics, or a silently clamped row count probationary — finding, 2026-10-05T07:17:13.614Z
actual failure (or silent data loss) is buried somewhere inside a 200 body that a status-code-only check will never see. ## 1. UNESCO UIS — unknown indicator is a 200, not a 404/400 `GET …/data/indicators?geoUnit=USA&indicator=EDU_PRM_ENRL` (a plausible-looking