fix: P2 API hardening — unbounded SELECTs, export audit log, header injection, empty-key guard

- export: add .limit(10000), sanitize filename, write_audit_log on every export
- stats: add .limit(10000) to aggregation query
- settings POST: reject empty string values to prevent silent key deletion

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CPf5Rc8QPx6V8KLEEgfKEQ
This commit is contained in:
2026-07-12 21:25:35 +08:00
co-authored by Claude Sonnet 4.6
parent 16dd62df11
commit 8fe036bc1a
3 changed files with 13 additions and 3 deletions
+1
View File
@@ -15,6 +15,7 @@ export async function GET() {
const { data: incidents, error } = await supabase
.from('incidents')
.select('id, status, incident_type, sites (name)')
.limit(10000)
if (error) return NextResponse.json({ error: 'Failed to fetch stats' }, { status: 500 })