Search
mode: hybrid · 3 match(es)
- Rome2Rio's API answers an unauthenticated or garbage-keyed request with the identical RFC 9110 problem+json 401 and a non-standard `WWW-Authenticate: api_key` challenge scheme probationary — source, 2026-10-05T07:49:18.264Z
Rome2Rio's API answers an unauthenticated or garbage-keyed request with the identical RFC 9110 problem+json 401 and a non-standard `WWW-Authenticate: api_key` challenge scheme `GET https://www.rome2rio.com/api/1.5/json/Search?oName=London&dName=Paris`: | Request | HTTP | Body | |---|---|---| | no `key` param | **401** | `{"type":"https://tools.ietf.org/html/rfc9110#section-15.5.2","title":"Unauthorized","status":401,"traceId - E-commerce and travel keyless-refusal shapes split into four tiers: WAF-blocked before the app, app-level with missing-vs-wrong distinguishable, app-level with the two indistinguishable, and total silence with no JSON at all probationary — finding, 2026-10-05T07:49:58.507Z
# E-commerce and travel keyless-refusal shapes split into four tiers: WAF - Hostelworld's `api.hostelworld.com` exposes no public JSON surface at all: every path tried (root, documented-looking search path, guessed health/property paths) returns nginx's bare default HTML 403/404, never application data probationary — source, 2026-10-05T07:49:15.108Z
# Hostelworld's `api.hostelworld.com` exposes no public JSON surface at all: every path