fix: category cache refresh, API 404, redundancy mapping, cost/relation authz, voterToken exposure
Build & Push Docker Image / build (push) Successful in 8m33s

- Invalidate categories/features queries after creating/editing tools so new
  categories appear immediately in search, browse dropdown and tool form
- Always refetch categories/features when the combobox/suggestion inputs mount
- Return JSON 404 for unmatched /api routes instead of the SPA index.html
- Read the manually confirmed 'better tool' from the recommendation notes
  instead of using the min tool id in the redundancy dashboard
- Require admin for cost/relation update+delete endpoints
- Stop exposing the voter token in the ratings list response
- Fix parseInt type error on user id params (Express 5 params typing)
This commit is contained in:
opencode
2026-08-01 15:25:06 +02:00
parent 2b5f074a63
commit 0c6a35e841
10 changed files with 47 additions and 14 deletions
+2 -2
View File
@@ -9,7 +9,7 @@ import {
UpdateToolBody,
DeleteToolParams,
} from "@workspace/api-zod";
import { requireAuth } from "../middleware/auth";
import { requireAuth, requireAdmin } from "../middleware/auth";
import { requireFeature } from "../middleware/feature";
import { writeAuditLog } from "../lib/audit";
@@ -349,7 +349,7 @@ router.post("/tools/:id/relations", requireAuth, requireFeature("similar-tools")
res.status(201).json(relation);
});
router.delete("/tools/relations/:id", requireAuth, async (req, res): Promise<void> => {
router.delete("/tools/relations/:id", requireAdmin, async (req, res): Promise<void> => {
const id = Number(req.params.id);
if (isNaN(id)) { res.status(400).json({ error: "Invalid id" }); return; }