security(search): move DELETE /search/cache to protected path
This commit is contained in:
@@ -251,6 +251,39 @@ jsonpath "$.filtered" not exists
|
||||
jsonpath "$.total" not exists
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
# 6b — Regression pin for AuthZ audit #14 (2026-07-12).
|
||||
# `DELETE /api/admin/search/cache` calls moka `invalidate_all()`
|
||||
# on the shared results cache — one call cold-starts every
|
||||
# subsequent search for every tenant. Pre-fix, this lived at
|
||||
# `/api/search/cache` gated only by the top-level auth
|
||||
# middleware: any authenticated caller (including external /
|
||||
# magic-link accounts) could DELETE it in a loop and hold the
|
||||
# results cache empty indefinitely (sustained DoS). Fix: gate
|
||||
# on `require_admin` AND move the URL to `/api/admin/...` so
|
||||
# the taxonomy declares the intent up front. Moved 2026-07-17.
|
||||
#
|
||||
# Bob (regular user) → 403; missing token → 401; admin → 200.
|
||||
# The 200 confirms the admin path still works (no regression
|
||||
# on the operator debug lever the endpoint remains for).
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
DELETE {{base_url}}/api/admin/search/cache
|
||||
Authorization: Bearer {{bob_token}}
|
||||
|
||||
HTTP 403
|
||||
|
||||
|
||||
DELETE {{base_url}}/api/admin/search/cache
|
||||
|
||||
HTTP 401
|
||||
|
||||
|
||||
DELETE {{base_url}}/api/admin/search/cache
|
||||
Authorization: Bearer {{admin_token}}
|
||||
|
||||
HTTP 200
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
# 7 — Teardown: removing the folder recursively takes the files
|
||||
# with it, so a single DELETE is enough.
|
||||
|
||||
Reference in New Issue
Block a user