fix: batch bugfixes for search escaping, auth errors, CORS tests, and rate limit test - #547
Merged
Merged
Conversation
…rnOfficial#516) The authRateLimit keyGenerator appends ':auth' to distinguish auth endpoint limits from general rate limits. Update the test assertion to match the actual implementation.
…arnOfficial#513) Escape % and _ in user-provided search input before passing to ilike to prevent wildcard injection and unexpected query behavior.
…as auth failures (ChainLearnOfficial#514) Database and other infrastructure errors in the authGuard catch block were being converted to 'Invalid or expired token' UnauthorizedError, masking the real issue. Let infrastructure errors propagate so they reach the error handler as proper 500 responses.
…l#515) The config loader calls process.exit(1) when required env vars are missing and NODE_ENV is not 'test'. Set NODE_ENV to 'test' in all CORS tests so the test fallbacks activate properly.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #513, Closes #514, Closes #515, Closes #516
Type of Change
Summary
This PR fixes 4 bugs across search input handling, auth error propagation, and test infrastructure:
%and_in user search input before passing toiliketo prevent wildcard injection in course search queries.authGuard; let them propagate as proper 500 errors.NODE_ENV=testin CORS origin config tests so the test fallback path activates instead of callingprocess.exit(1).authRateLimittest assertion to expect"10.0.0.1:auth"to match the actual key format.Motivation / Context
Closes #513, Closes #514, Closes #515, Closes #516