From 8bc03f8d04d83a8c23d33d4ae80e5c06b86333f9 Mon Sep 17 00:00:00 2001 From: Josema Camacho Date: Tue, 7 Apr 2026 12:46:51 +0200 Subject: [PATCH] fix(api): remove clear_cache from attack paths read-only query endpoints (#10586) --- api/CHANGELOG.md | 1 + api/src/backend/api/tests/test_views.py | 12 ------------ api/src/backend/api/v1/views.py | 2 -- 3 files changed, 1 insertion(+), 14 deletions(-) diff --git a/api/CHANGELOG.md b/api/CHANGELOG.md index 43b836d4da..56190e60bf 100644 --- a/api/CHANGELOG.md +++ b/api/CHANGELOG.md @@ -28,6 +28,7 @@ All notable changes to the **Prowler API** are documented in this file. - Membership `post_delete` signal using raw FK ids to avoid `DoesNotExist` during cascade deletions [(#10497)](https://github.com/prowler-cloud/prowler/pull/10497) - Finding group resources endpoints returning false 404 when filters match no results, and `sort` parameter being ignored [(#10510)](https://github.com/prowler-cloud/prowler/pull/10510) - Jira integration failing with `JiraInvalidIssueTypeError` on non-English Jira instances due to hardcoded `"Task"` issue type; now dynamically fetches available issue types per project [(#10534)](https://github.com/prowler-cloud/prowler/pull/10534) +- Attack Paths: Remove `clear_cache` call from read-only query endpoints; cache clearing belongs to the scan/ingestion flow, not API queries [(#10586)](https://github.com/prowler-cloud/prowler/pull/10586) ### 🔐 Security diff --git a/api/src/backend/api/tests/test_views.py b/api/src/backend/api/tests/test_views.py index 3fcd515f6a..d30e786e5f 100644 --- a/api/src/backend/api/tests/test_views.py +++ b/api/src/backend/api/tests/test_views.py @@ -4287,7 +4287,6 @@ class TestAttackPathsScanViewSet: "api.v1.views.attack_paths_views_helpers.execute_query", return_value=graph_payload, ) as mock_execute, - patch("api.v1.views.graph_database.clear_cache") as mock_clear_cache, ): response = authenticated_client.post( reverse( @@ -4314,7 +4313,6 @@ class TestAttackPathsScanViewSet: prepared_parameters, provider_id, ) - mock_clear_cache.assert_called_once_with(expected_db_name) result = response.json()["data"] attributes = result["attributes"] assert attributes["nodes"] == graph_payload["nodes"] @@ -4369,7 +4367,6 @@ class TestAttackPathsScanViewSet: "api.v1.views.attack_paths_views_helpers.execute_query", return_value=graph_payload, ), - patch("api.v1.views.graph_database.clear_cache"), ): response = authenticated_client.post( reverse( @@ -4453,7 +4450,6 @@ class TestAttackPathsScanViewSet: "truncated": False, }, ), - patch("api.v1.views.graph_database.clear_cache"), patch( "api.v1.views.graph_database.get_database_name", return_value="db-test" ), @@ -4508,7 +4504,6 @@ class TestAttackPathsScanViewSet: "truncated": False, }, ), - patch("api.v1.views.graph_database.clear_cache"), patch( "api.v1.views.graph_database.get_database_name", return_value="db-test" ), @@ -4588,7 +4583,6 @@ class TestAttackPathsScanViewSet: "truncated": False, }, ), - patch("api.v1.views.graph_database.clear_cache"), ): response = authenticated_client.post( reverse( @@ -4654,7 +4648,6 @@ class TestAttackPathsScanViewSet: "api.v1.views.graph_database.get_database_name", return_value="db-test", ), - patch("api.v1.views.graph_database.clear_cache"), ): response = authenticated_client.post( reverse( @@ -4711,7 +4704,6 @@ class TestAttackPathsScanViewSet: "api.v1.views.graph_database.get_database_name", return_value="db-test", ), - patch("api.v1.views.graph_database.clear_cache"), ): response = authenticated_client.post( reverse( @@ -4758,7 +4750,6 @@ class TestAttackPathsScanViewSet: "api.v1.views.graph_database.get_database_name", return_value="db-test", ), - patch("api.v1.views.graph_database.clear_cache"), ): response = authenticated_client.post( reverse( @@ -5109,9 +5100,6 @@ class TestAttackPathsScanViewSet: "api.v1.views.graph_database.get_database_name", return_value="db-test", ), - patch( - "api.v1.views.graph_database.clear_cache", - ), ): for i in range(11): response = authenticated_client.post( diff --git a/api/src/backend/api/v1/views.py b/api/src/backend/api/v1/views.py index cf4f752052..32c7834274 100644 --- a/api/src/backend/api/v1/views.py +++ b/api/src/backend/api/v1/views.py @@ -2628,7 +2628,6 @@ class AttackPathsScanViewSet(BaseRLSViewSet): provider_id, ) query_duration = time.monotonic() - start - graph_database.clear_cache(database_name) result_nodes = len(graph.get("nodes", [])) result_relationships = len(graph.get("relationships", [])) @@ -2696,7 +2695,6 @@ class AttackPathsScanViewSet(BaseRLSViewSet): provider_id, ) query_duration = time.monotonic() - start - graph_database.clear_cache(database_name) query_length = len(serializer.validated_data["query"]) result_nodes = len(graph.get("nodes", []))