fix(015): remove SQL LIMIT injection — enforce in Go only
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
parent
bd1bccc692
commit
e5ee8d16e4
@@ -206,15 +206,13 @@ channel_messages AS (
|
||||
trimmed = strings.TrimRight(trimmed, "; \t\n")
|
||||
|
||||
if strings.HasPrefix(upper, "WITH") {
|
||||
// User has their own CTEs. We need to merge them.
|
||||
// Strategy: our CTEs come first, then append user's CTEs after a comma.
|
||||
// Remove the user's "WITH " prefix since our CTE block already has WITH.
|
||||
// User has their own CTEs. Merge: our CTEs first, then theirs.
|
||||
userCTEs := strings.TrimSpace(trimmed[4:]) // skip "WITH"
|
||||
return cte + ", " + userCTEs + " LIMIT " + fmt.Sprintf("%d", MaxRows+1)
|
||||
return cte + ", " + userCTEs
|
||||
}
|
||||
|
||||
// Simple SELECT — prepend our CTEs
|
||||
return cte + trimmed + " LIMIT " + fmt.Sprintf("%d", MaxRows+1)
|
||||
return cte + trimmed
|
||||
}
|
||||
|
||||
// quoteSQLString safely quotes a string for use in SQL.
|
||||
|
||||
Reference in New Issue
Block a user