fix(015): remove SQL LIMIT injection — enforce in Go only

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
Algis Dumbris
2026-03-26 07:19:38 +02:00
co-authored by Claude Opus 4.6
parent bd1bccc692
commit e5ee8d16e4
+3 -5
View File
@@ -206,15 +206,13 @@ channel_messages AS (
trimmed = strings.TrimRight(trimmed, "; \t\n")
if strings.HasPrefix(upper, "WITH") {
// User has their own CTEs. We need to merge them.
// Strategy: our CTEs come first, then append user's CTEs after a comma.
// Remove the user's "WITH " prefix since our CTE block already has WITH.
// User has their own CTEs. Merge: our CTEs first, then theirs.
userCTEs := strings.TrimSpace(trimmed[4:]) // skip "WITH"
return cte + ", " + userCTEs + " LIMIT " + fmt.Sprintf("%d", MaxRows+1)
return cte + ", " + userCTEs
}
// Simple SELECT — prepend our CTEs
return cte + trimmed + " LIMIT " + fmt.Sprintf("%d", MaxRows+1)
return cte + trimmed
}
// quoteSQLString safely quotes a string for use in SQL.