aboutsummaryrefslogtreecommitdiffstats
path: root/internal/web/search_test.go
diff options
context:
space:
mode:
authorgrm <grm@eyesin.space>2026-09-18 13:50:35 +0300
committergrm <grm@eyesin.space>2026-09-18 13:50:42 +0300
commitc3026c34b042cc044cddfc5674d5f5ad69bb845d (patch)
tree7111e8fc310b193c510110e813befb00695a7597 /internal/web/search_test.go
parentc47397ac1e2ceafafe2be3cdec86366dd396ed6f (diff)
downloadblogspace-c3026c34b042cc044cddfc5674d5f5ad69bb845d.tar.gz
blogspace-c3026c34b042cc044cddfc5674d5f5ad69bb845d.tar.bz2
blogspace-c3026c34b042cc044cddfc5674d5f5ad69bb845d.zip
Security: Throttle search, cap its words and give the query a deadline
/search runs an unindexed regular-expression scan over every published post, built from up to fifty ".*"-joined words, for anyone who asks — the cheapest way for a bot to keep Postgres busy. Queries are now cut at eight words (more never improve the answer), each address gets thirty searches and then thirty a minute, and the statement is cancelled after five seconds; a timeout reads as no results and is logged, rather than a 500. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
Diffstat (limited to 'internal/web/search_test.go')
-rw-r--r--internal/web/search_test.go11
1 files changed, 6 insertions, 5 deletions
diff --git a/internal/web/search_test.go b/internal/web/search_test.go
index 6ced39b..7ade83f 100644
--- a/internal/web/search_test.go
+++ b/internal/web/search_test.go
@@ -10,11 +10,12 @@ import (
func TestSearchPattern(t *testing.T) {
for q, want := range map[string]string{
- "go tem": "go.*tem",
- " a.b (c) ": `a\.b.*\(c\)`,
- "one": "one",
- " ": "",
- "": "",
+ "go tem": "go.*tem",
+ " a.b (c) ": `a\.b.*\(c\)`,
+ "one": "one",
+ " ": "",
+ "": "",
+ "a b c d e f g h i j": "a.*b.*c.*d.*e.*f.*g.*h", // maxSearchWords
} {
if got := searchPattern(q); got != want {
t.Errorf("searchPattern(%q) = %q, want %q", q, got, want)