fix: audit round 3 — IDOR report-scoping, auth rate-limit, briefing chat scoping, DailyVolumes dedup, N+1 list routines, FE export/ask error handling
- IDOR: interrogate without report_id now scoped to user_key (LatestReportForUser); regression test TestInterrogateIDORScoped - auth: signup/login per-IP rate limit 10/60s (new internal/api/ratelimit.go) + test - chat unscoped grounding: build caller's own briefing instead of global LatestBriefing - DailyVolumes: dedupe by bar date (snapshot rows hold 30-day windows) — fixes volume-anomaly skew - GetDestination: direct (id,user_key) query instead of listing all - ListRoutines: single LastRunsByRoutine query instead of N+1 RunHistory - FE: exportMd/ask/HTML/PDF export now surface errors; alerts create clears channels
This commit is contained in:
@@ -28,11 +28,16 @@ func (s *Server) ListRoutines(w http.ResponseWriter, r *http.Request) {
|
||||
LastRun any `json:"last_run"`
|
||||
}
|
||||
out := make([]rowOut, 0, len(rows))
|
||||
lastByRoutine, lerr := s.DB.LastRunsByRoutine(s.userKey(r))
|
||||
if lerr != nil {
|
||||
lastByRoutine = nil
|
||||
}
|
||||
for _, row := range rows {
|
||||
hist, _ := s.DB.RunHistory(row.ID, 1)
|
||||
var last any
|
||||
if len(hist) > 0 {
|
||||
last = hist[0]
|
||||
if lastByRoutine != nil {
|
||||
if v, ok := lastByRoutine[row.ID]; ok {
|
||||
last = v
|
||||
}
|
||||
}
|
||||
out = append(out, rowOut{row, last})
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user