[web] refactor an insecure web-api endpoint into a script GitOrigin-RevId: ba565a41d11fdaeb919dbf3cfe80c6f2e2474df1