fix: audit round 3 — IDOR report-scoping, auth rate-limit, briefing chat scoping, DailyVolumes dedup, N+1 list routines, FE export/ask error handling
- IDOR: interrogate without report_id now scoped to user_key (LatestReportForUser); regression test TestInterrogateIDORScoped - auth: signup/login per-IP rate limit 10/60s (new internal/api/ratelimit.go) + test - chat unscoped grounding: build caller's own briefing instead of global LatestBriefing - DailyVolumes: dedupe by bar date (snapshot rows hold 30-day windows) — fixes volume-anomaly skew - GetDestination: direct (id,user_key) query instead of listing all - ListRoutines: single LastRunsByRoutine query instead of N+1 RunHistory - FE: exportMd/ask/HTML/PDF export now surface errors; alerts create clears channels
This commit is contained in:
@@ -69,8 +69,13 @@ func (s *Server) Router() http.Handler {
|
||||
r.Get("/auth/callback", s.AuthCallback)
|
||||
r.Get("/auth/me", s.AuthMe)
|
||||
r.Post("/auth/logout", s.AuthLogout)
|
||||
r.Post("/auth/signup", s.AuthSignup)
|
||||
r.Post("/auth/login", s.AuthLogin)
|
||||
// Rate-limited auth endpoints: max 10 per IP per 60s.
|
||||
authRL := newIPRateLimiter(10, 60*time.Second)
|
||||
r.Group(func(r chi.Router) {
|
||||
r.Use(func(next http.Handler) http.Handler { return s.rateLimitAuth(authRL, next) })
|
||||
r.Post("/auth/signup", s.AuthSignup)
|
||||
r.Post("/auth/login", s.AuthLogin)
|
||||
})
|
||||
r.Get("/version", s.Version)
|
||||
// Publik baca: dashboard bisa dibuka tanpa login. Fitur + filter di bawah
|
||||
// wajib login (session cookie, tanpa demo bypass).
|
||||
|
||||
Reference in New Issue
Block a user