Skip to content

fix: batch bugfixes for search escaping, auth errors, CORS tests, and rate limit test - #547

Merged
DeFiVC merged 4 commits into
ChainLearnOfficial:mainfrom
KidDev88:fix/batch-bugfixes
Oct 1, 2026
Merged

DeFiVC merged 4 commits into
ChainLearnOfficial:mainfrom
KidDev88:fix/batch-bugfixes

Conversation

@KidDev88

@KidDev88 KidDev88 commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Closes #513, Closes #514, Closes #515, Closes #516

Type of Change

  • Bug fix (non-breaking change that fixes an issue)
  • New feature (non-breaking change that adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Refactoring (no functional or behavioral changes)
  • Performance improvement
  • Documentation update
  • Build / CI configuration change
  • Dependency update
  • Other:

Summary

This PR fixes 4 bugs across search input handling, auth error propagation, and test infrastructure:

  1. Escape LIKE pattern characters in course search queries #513 — Escape % and _ in user search input before passing to ilike to prevent wildcard injection in course search queries.
  2. Improve error handling in authGuard for Redis failures #514 — Stop masking database/infrastructure errors as "Invalid or expired token" in authGuard; let them propagate as proper 500 errors.
  3. Fix 5 failing CORS origin configuration tests #515 — Set NODE_ENV=test in CORS origin config tests so the test fallback path activates instead of calling process.exit(1).
  4. Fix rate limit test assertion for auth endpoint key format #516 — Update the authRateLimit test assertion to expect "10.0.0.1:auth" to match the actual key format.

Motivation / Context

Closes #513, Closes #514, Closes #515, Closes #516

…rnOfficial#516)

The authRateLimit keyGenerator appends ':auth' to distinguish auth
endpoint limits from general rate limits. Update the test assertion
to match the actual implementation.
…arnOfficial#513)

Escape % and _ in user-provided search input before passing to ilike
to prevent wildcard injection and unexpected query behavior.
…as auth failures (ChainLearnOfficial#514)

Database and other infrastructure errors in the authGuard catch block
were being converted to 'Invalid or expired token' UnauthorizedError,
masking the real issue. Let infrastructure errors propagate so they
reach the error handler as proper 500 responses.
…l#515)

The config loader calls process.exit(1) when required env vars are
missing and NODE_ENV is not 'test'. Set NODE_ENV to 'test' in all
CORS tests so the test fallbacks activate properly.
@DeFiVC
DeFiVC merged commit a0443f2 into ChainLearnOfficial:main Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants