Require a session on POST ****************

FixDocsService
Shipped
August 2, 2026 at 6:38 PM UTC
Author
Kamo
Commit
2f182ed

The handler took an HttpServletRequest but never used it, carrying the comment "No auth required — internal admin maintenance endpoint". APIService relays /api/docs/** without gateway authentication and DocsService permits every request, so this was an anonymous, internet-reachable trigger for a sweep that reads document bytes belonging to every tenant via an unscoped findAll. Roughly eighteen other handlers in this controller already resolve a caller via extractKToken(request); this one was an omission, not a design. Adds the first test to this service. The sweep stays deliberately platform-wide. Restricting it to platform staff needs a god-mode signal here and belongs with the deny-by-default authorization work.

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing