diff options
Diffstat (limited to 'internal/web/handlers_blog.go')
| -rw-r--r-- | internal/web/handlers_blog.go | 10 |
1 files changed, 6 insertions, 4 deletions
diff --git a/internal/web/handlers_blog.go b/internal/web/handlers_blog.go index d9caf22..f138c58 100644 --- a/internal/web/handlers_blog.go +++ b/internal/web/handlers_blog.go @@ -67,13 +67,15 @@ func (s *Server) blogView(r *http.Request) (map[string]any, error) { // (typed, so the layout's index lookups still work). var noNotices = map[string][]Notice{} +// maxPageNum bounds ?p=: no listing is that long, and (n-1)*per must not +// overflow into a negative OFFSET, which Postgres refuses (a 500 for a bot to +// trigger at will). +const maxPageNum = 100000 + // pageNum reads the ?p= of a paginated listing (1 when absent or silly). func pageNum(r *http.Request) int { n, _ := strconv.Atoi(r.URL.Query().Get("p")) - if n < 1 { - n = 1 - } - return n + return min(max(n, 1), maxPageNum) } func (s *Server) handleBlogHome(w http.ResponseWriter, r *http.Request) { |
