security(search): move DELETE /search/cache to protected path

This commit is contained in:
Edouard Vanbelle
2026-07-17 00:43:15 +02:00
parent eb884f6c8f
commit dd72b77c22
6 changed files with 104 additions and 31 deletions
+33
View File
@@ -251,6 +251,39 @@ jsonpath "$.filtered" not exists
jsonpath "$.total" not exists
# ─────────────────────────────────────────────────────────────
# 6b — Regression pin for AuthZ audit #14 (2026-07-12).
# `DELETE /api/admin/search/cache` calls moka `invalidate_all()`
# on the shared results cache — one call cold-starts every
# subsequent search for every tenant. Pre-fix, this lived at
# `/api/search/cache` gated only by the top-level auth
# middleware: any authenticated caller (including external /
# magic-link accounts) could DELETE it in a loop and hold the
# results cache empty indefinitely (sustained DoS). Fix: gate
# on `require_admin` AND move the URL to `/api/admin/...` so
# the taxonomy declares the intent up front. Moved 2026-07-17.
#
# Bob (regular user) → 403; missing token → 401; admin → 200.
# The 200 confirms the admin path still works (no regression
# on the operator debug lever the endpoint remains for).
# ─────────────────────────────────────────────────────────────
DELETE {{base_url}}/api/admin/search/cache
Authorization: Bearer {{bob_token}}
HTTP 403
DELETE {{base_url}}/api/admin/search/cache
HTTP 401
DELETE {{base_url}}/api/admin/search/cache
Authorization: Bearer {{admin_token}}
HTTP 200
# ─────────────────────────────────────────────────────────────
# 7 — Teardown: removing the folder recursively takes the files
# with it, so a single DELETE is enough.