security(search): move DELETE /search/cache to protected path

This commit is contained in:
Edouard Vanbelle
2026-07-17 00:43:15 +02:00
parent eb884f6c8f
commit dd72b77c22
6 changed files with 104 additions and 31 deletions
+7 -2
View File
@@ -69,9 +69,14 @@ export function searchSuggest(
});
}
/** Clear the server-side search cache (`DELETE /api/search/cache`). */
/**
* Clear the shared server-side search cache
* (`DELETE /api/admin/search/cache`). Admin-only — moved from
* `/api/search/cache` on 2026-07-17 because the underlying
* `invalidate_all()` touches every tenant (see AuthZ audit #14).
*/
export async function clearSearchCache(): Promise<void> {
const res = await apiFetch('/api/search/cache', {
const res = await apiFetch('/api/admin/search/cache', {
method: 'DELETE',
credentials: 'same-origin'
});