fix: audit round 3 — IDOR report-scoping, auth rate-limit, briefing chat scoping, DailyVolumes dedup, N+1 list routines, FE export/ask error handling

- IDOR: interrogate without report_id now scoped to user_key (LatestReportForUser); regression test TestInterrogateIDORScoped
- auth: signup/login per-IP rate limit 10/60s (new internal/api/ratelimit.go) + test
- chat unscoped grounding: build caller's own briefing instead of global LatestBriefing
- DailyVolumes: dedupe by bar date (snapshot rows hold 30-day windows) — fixes volume-anomaly skew
- GetDestination: direct (id,user_key) query instead of listing all
- ListRoutines: single LastRunsByRoutine query instead of N+1 RunHistory
- FE: exportMd/ask/HTML/PDF export now surface errors; alerts create clears channels
This commit is contained in:
asepharyana
2026-09-16 14:12:32 +07:00
parent 0b00daed39
commit 1ec860f9be
9 changed files with 270 additions and 38 deletions
+1 -1
View File
@@ -64,7 +64,7 @@ func (s *Server) loadReport(ticker string, id int64, userKey string) (string, st
}
return p, c, at, rid, nil
}
p, c, at, err := s.DB.LatestReport(ticker)
p, c, at, err := s.DB.LatestReportForUser(ticker, userKey)
if err != nil {
return "", "", "", 0, err
}