Commit 318f5b6
committed
fix(api): escape $regex value and scope filter allowlist to mongo fields
The contains operator on the mongo store passed the caller-supplied
string straight to $regex, letting metacharacters match unintended
patterns. Escape the value with regexp.QuoteMeta so only literal
substring matching is performed. Drop PG-native flat field names from
the device filter allowlist since the mongo schema only exposes the
nested paths (identity.mac, info.platform).1 parent 0b773b9 commit 318f5b6
2 files changed
Lines changed: 5 additions & 4 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
24 | 24 | | |
25 | 25 | | |
26 | 26 | | |
27 | | - | |
28 | 27 | | |
29 | | - | |
30 | 28 | | |
31 | 29 | | |
32 | 30 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
| 6 | + | |
6 | 7 | | |
7 | 8 | | |
8 | 9 | | |
| |||
57 | 58 | | |
58 | 59 | | |
59 | 60 | | |
| 61 | + | |
| 62 | + | |
60 | 63 | | |
61 | | - | |
| 64 | + | |
62 | 65 | | |
63 | | - | |
| 66 | + | |
64 | 67 | | |
65 | 68 | | |
66 | 69 | | |
| |||
0 commit comments