The dashboard Clear-all button posts to /imaging/delete-all but the form was missing the hidden _csrf_token input that the rest of the webapp's POST forms include, so the endpoint would reject the request when CSRF enforcement is active.