fix: audit round 2 — session cookie Secure kondisional, logout clear cookie, IDOR report owner-scoping (migrasi 0008), health force login-gate, SSE stream login-gate, FE: Gate undefined-flicker, auth-expired global redirect, X-User-Key demo dihapus, error handling alerts/routines/watchlist, chart label, encodeURIComponent, Screener onMount
This commit is contained in:
@@ -28,13 +28,13 @@ func (s *Server) Chat(w http.ResponseWriter, r *http.Request) {
|
||||
writeErr(w, http.StatusUnprocessableEntity, "message is required")
|
||||
return
|
||||
}
|
||||
// Scope grounding: report citations when scoped.
|
||||
// Scope grounding: report citations when scoped (owner-scoped).
|
||||
var ground, citesRaw string
|
||||
if req.Scope != nil && req.Scope.ReportID > 0 {
|
||||
var cites string
|
||||
var at string
|
||||
err := s.DB.QueryRow(`SELECT payload_json, citations_json, generated_at FROM reports WHERE id=?`,
|
||||
req.Scope.ReportID).Scan(&ground, &cites, &at)
|
||||
err := s.DB.QueryRow(`SELECT payload_json, citations_json, generated_at FROM reports WHERE id=? AND user_key=?`,
|
||||
req.Scope.ReportID, s.userKey(r)).Scan(&ground, &cites, &at)
|
||||
if err != nil {
|
||||
writeErr(w, http.StatusNotFound, "report not found")
|
||||
return
|
||||
|
||||
Reference in New Issue
Block a user