fix(search): harden authorized results and ordering

This commit is contained in:
2026-07-21 17:42:22 +08:00
parent 000de4bcdb
commit 8cc130244b
12 changed files with 405 additions and 64 deletions

View File

@@ -1,7 +1,10 @@
package search
import (
"fmt"
"sort"
"strings"
"time"
"gorm.io/gorm"
"senlinai-agent/backend/internal/models"
@@ -11,7 +14,15 @@ type Service struct {
db *gorm.DB
}
const maxSearchResults = 50
const (
maxSearchResults = 50
maxSearchSnippetRunes = 240
)
type rankedSearchResult struct {
result SearchResultDTO
updatedAt time.Time
}
// SearchResultDTO 是搜索接口的稳定结果,所有关联均使用公开 identity。
type SearchResultDTO struct {
@@ -42,84 +53,110 @@ func (s *Service) Search(userID uint, query string) ([]SearchResultDTO, error) {
if query == "" {
return []SearchResultDTO{}, nil
}
if s.database().Dialector.Name() == "postgres" {
return s.searchPostgres(userID, query)
}
like := containsPattern(query)
results := []SearchResultDTO{}
operator := "LIKE"
if s.database().Dialector.Name() == "postgres" {
operator = "ILIKE"
}
var projects []models.SenlinAgentProject
if err := s.database().Where("owner_id = ? AND (name LIKE ? ESCAPE '!' OR description LIKE ? ESCAPE '!')", userID, like, like).Limit(maxSearchResults).Find(&projects).Error; err != nil {
projectFilter := fmt.Sprintf("owner_id = ? AND (name %s ? ESCAPE '!' OR description %s ? ESCAPE '!')", operator, operator)
if err := s.database().Where(projectFilter, userID, like, like).
Order("updated_at DESC").Order("identity ASC").
Limit(maxSearchResults).Find(&projects).Error; err != nil {
return nil, err
}
projectResults := make([]rankedSearchResult, 0, len(projects))
for _, project := range projects {
results = append(results, SearchResultDTO{Type: "project", ID: project.Identity, ProjectID: project.Identity, Title: project.Name, Snippet: project.Description})
projectResults = append(projectResults, rankedSearchResult{
result: SearchResultDTO{Type: "project", ID: project.Identity, ProjectID: project.Identity, Title: project.Name, Snippet: project.Description},
updatedAt: project.UpdatedAt,
})
}
var tasks []models.SenlinAgentTask
taskFilter := fmt.Sprintf("(senlin_agent_projects.owner_id = ? OR senlin_agent_tasks.assignee_id = ?) AND (senlin_agent_tasks.title %s ? ESCAPE '!' OR senlin_agent_tasks.description %s ? ESCAPE '!')", operator, operator)
if err := s.database().Select("senlin_agent_tasks.*").Joins("JOIN senlin_agent_projects ON senlin_agent_projects.id = senlin_agent_tasks.project_id").
Where("(senlin_agent_projects.owner_id = ? OR senlin_agent_tasks.assignee_id = ?) AND (senlin_agent_tasks.title LIKE ? ESCAPE '!' OR senlin_agent_tasks.description LIKE ? ESCAPE '!')", userID, userID, like, like).
Where(taskFilter, userID, userID, like, like).
Order("senlin_agent_tasks.updated_at DESC").Order("senlin_agent_tasks.identity ASC").
Limit(maxSearchResults).
Find(&tasks).Error; err != nil {
return nil, err
}
taskResults := make([]rankedSearchResult, 0, len(tasks))
for _, task := range tasks {
results = append(results, SearchResultDTO{Type: "task", ID: task.Identity, ProjectID: task.ProjectIdentity, Title: task.Title, Snippet: task.Description})
taskResults = append(taskResults, rankedSearchResult{
result: SearchResultDTO{Type: "task", ID: task.Identity, ProjectID: task.ProjectIdentity, Title: task.Title, Snippet: task.Description},
updatedAt: task.UpdatedAt,
})
}
var notes []models.SenlinAgentNote
if err := s.database().Select("senlin_agent_notes.*").Joins("JOIN senlin_agent_projects ON senlin_agent_projects.id = senlin_agent_notes.project_id").
Where(`(senlin_agent_projects.owner_id = ? OR EXISTS (
noteFilter := fmt.Sprintf(`(senlin_agent_projects.owner_id = ? OR EXISTS (
SELECT 1 FROM senlin_agent_task_shares
JOIN senlin_agent_tasks ON senlin_agent_tasks.id = senlin_agent_task_shares.task_id
WHERE senlin_agent_task_shares.object_type = 'note'
AND senlin_agent_task_shares.object_id = senlin_agent_notes.id
AND senlin_agent_tasks.project_id = senlin_agent_notes.project_id
AND senlin_agent_tasks.assignee_id = ?
)) AND (senlin_agent_notes.title LIKE ? ESCAPE '!' OR senlin_agent_notes.markdown LIKE ? ESCAPE '!')`, userID, userID, like, like).
)) AND (senlin_agent_notes.title %s ? ESCAPE '!' OR senlin_agent_notes.markdown %s ? ESCAPE '!')`, operator, operator)
if err := s.database().Select("senlin_agent_notes.*").Joins("JOIN senlin_agent_projects ON senlin_agent_projects.id = senlin_agent_notes.project_id").
Where(noteFilter, userID, userID, like, like).
Order("senlin_agent_notes.updated_at DESC").Order("senlin_agent_notes.identity ASC").
Limit(maxSearchResults).
Find(&notes).Error; err != nil {
return nil, err
}
noteResults := make([]rankedSearchResult, 0, len(notes))
for _, note := range notes {
results = append(results, SearchResultDTO{Type: "note", ID: note.Identity, ProjectID: note.ProjectIdentity, Title: note.Title, Snippet: note.Markdown})
noteResults = append(noteResults, rankedSearchResult{
result: SearchResultDTO{Type: "note", ID: note.Identity, ProjectID: note.ProjectIdentity, Title: note.Title, Snippet: note.Markdown},
updatedAt: note.UpdatedAt,
})
}
if len(results) > maxSearchResults {
results = results[:maxSearchResults]
}
return results, nil
return stableFairLimit(projectResults, taskResults, noteResults), nil
}
func (s *Service) searchPostgres(userID uint, query string) ([]SearchResultDTO, error) {
var results []SearchResultDTO
like := containsPattern(query)
err := s.database().Raw(`
SELECT 'project' AS type, p.identity AS id, p.identity AS project_id, p.name AS title, p.description AS snippet
FROM senlin_agent_projects p
WHERE p.owner_id = ?
AND (coalesce(p.name, '') ILIKE ? ESCAPE '!' OR coalesce(p.description, '') ILIKE ? ESCAPE '!')
UNION ALL
SELECT 'task' AS type, t.identity AS id, p.identity AS project_id, t.title, t.description AS snippet
FROM senlin_agent_tasks t
JOIN senlin_agent_projects p ON p.id = t.project_id
WHERE (p.owner_id = ? OR t.assignee_id = ?)
AND (coalesce(t.title, '') ILIKE ? ESCAPE '!' OR coalesce(t.description, '') ILIKE ? ESCAPE '!')
UNION ALL
SELECT 'note' AS type, n.identity AS id, p.identity AS project_id, n.title, n.markdown AS snippet
FROM senlin_agent_notes n
JOIN senlin_agent_projects p ON p.id = n.project_id
WHERE (p.owner_id = ? OR EXISTS (
SELECT 1 FROM senlin_agent_task_shares ts
JOIN senlin_agent_tasks t ON t.id = ts.task_id
WHERE ts.object_type = 'note'
AND ts.object_id = n.id
AND t.project_id = n.project_id
AND t.assignee_id = ?
))
AND (coalesce(n.title, '') ILIKE ? ESCAPE '!' OR coalesce(n.markdown, '') ILIKE ? ESCAPE '!')
LIMIT ?
`, userID, like, like, userID, userID, like, like, userID, userID, like, like, maxSearchResults).Scan(&results).Error
return results, err
func stableFairLimit(buckets ...[]rankedSearchResult) []SearchResultDTO {
for _, bucket := range buckets {
sort.Slice(bucket, func(left, right int) bool {
if bucket[left].updatedAt.Equal(bucket[right].updatedAt) {
return bucket[left].result.ID < bucket[right].result.ID
}
return bucket[left].updatedAt.After(bucket[right].updatedAt)
})
}
results := make([]SearchResultDTO, 0, maxSearchResults)
for position := 0; len(results) < maxSearchResults; position++ {
added := false
for _, bucket := range buckets {
if position >= len(bucket) {
continue
}
result := bucket[position].result
result.Snippet = boundedSnippet(result.Snippet)
results = append(results, result)
added = true
if len(results) == maxSearchResults {
return results
}
}
if !added {
return results
}
}
return results
}
func boundedSnippet(value string) string {
runes := []rune(value)
if len(runes) <= maxSearchSnippetRunes {
return value
}
return string(runes[:maxSearchSnippetRunes])
}
func containsPattern(query string) string {