From e5ee8d16e4bb8857822faaf55cae9193dc61a6e4 Mon Sep 17 00:00:00 2001 From: Algis Dumbris Date: Thu, 26 Mar 2026 07:19:38 +0200 Subject: [PATCH] =?UTF-8?q?fix(015):=20remove=20SQL=20LIMIT=20injection=20?= =?UTF-8?q?=E2=80=94=20enforce=20in=20Go=20only?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-Authored-By: Claude Opus 4.6 (1M context) --- internal/agentquery/executor.go | 8 +++----- 1 file changed, 3 insertions(+), 5 deletions(-) diff --git a/internal/agentquery/executor.go b/internal/agentquery/executor.go index 696224a..b7ad440 100644 --- a/internal/agentquery/executor.go +++ b/internal/agentquery/executor.go @@ -206,15 +206,13 @@ channel_messages AS ( trimmed = strings.TrimRight(trimmed, "; \t\n") if strings.HasPrefix(upper, "WITH") { - // User has their own CTEs. We need to merge them. - // Strategy: our CTEs come first, then append user's CTEs after a comma. - // Remove the user's "WITH " prefix since our CTE block already has WITH. + // User has their own CTEs. Merge: our CTEs first, then theirs. userCTEs := strings.TrimSpace(trimmed[4:]) // skip "WITH" - return cte + ", " + userCTEs + " LIMIT " + fmt.Sprintf("%d", MaxRows+1) + return cte + ", " + userCTEs } // Simple SELECT — prepend our CTEs - return cte + trimmed + " LIMIT " + fmt.Sprintf("%d", MaxRows+1) + return cte + trimmed } // quoteSQLString safely quotes a string for use in SQL.