- Step 11: Add defensive column existence validation in apply_sorting
- JSON Schema: Remove array and object types from default field oneOf
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Use sanitize_sql_array for ORDER BY in full-text search (step 6, 9)
- Use Arel nodes for safer sorting implementation (step 11)
- Add comprehensive array query security examples (step 5)
- Add type validation to JSON schema default property
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Fix remaining SQLi vulnerability in step 9 section 9.8
- Replace Arel send() with safer order(hash) in step 11
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Fix search scope to use connection.quote instead of sanitize_sql_like
- Improve apply_sorting to use Arel for safer SQL generation
- Fix apply_filters to use params.slice for whitelist validation
- Add security notes for array column queries
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>