Files
tomsjavajive/api
Myron Blair bdd0bd6afa Require admin auth on api/search-customers.php
Was callable anonymously, leaking customer email/phone/wallet balance/reward
points to anyone who could guess a search term. Gated behind AdminAuth,
matching the pattern used elsewhere (401 JSON response, not a redirect,
since this is an API endpoint called via fetch from admin/pos.php).
2026-07-05 15:23:33 +00:00
..
2026-05-22 12:52:44 +00:00
2026-05-22 12:52:44 +00:00
2026-05-22 12:52:44 +00:00
2026-05-22 12:52:44 +00:00
2026-05-22 12:52:44 +00:00
2026-05-22 12:52:44 +00:00
2026-05-22 12:52:44 +00:00
2026-05-22 12:52:44 +00:00
2026-05-22 12:52:44 +00:00
2026-05-22 12:52:44 +00:00