feat(09-04): execute allowlisted deterministic list queries

- Search, sort, filters, and pagination use compiled selectors and bound values
- Equal sort keys break ties on the primary key so adjacent pages do not overlap
- Unknown identifiers return validation_failed before SQL
This commit is contained in:
Jakub Zych
2026-09-24 19:03:44 +02:00
parent 7f451c3572
commit 6a57f63e81
3 changed files with 537 additions and 55 deletions

View File

@@ -129,11 +129,19 @@ func WriteData(w http.ResponseWriter, status int, data, meta any) {
// WriteError writes a D-10 error envelope. details is always an object.
func WriteError(w http.ResponseWriter, status int, code, message string) {
WriteErrorDetails(w, status, code, message, nil)
}
// WriteErrorDetails writes a D-10 error envelope with field messages.
func WriteErrorDetails(w http.ResponseWriter, status int, code, message string, details map[string]any) {
if details == nil {
details = map[string]any{}
}
writeJSON(w, status, map[string]any{
"error": map[string]any{
"code": code,
"message": message,
"details": map[string]any{},
"details": details,
},
})
}