Parent: #244
Epic: #15
Severity: Medium
Execution mode: AFK
What to build
Make every production report path bounded under authenticated but hostile use. Current report generation can load all matching history and perform repeated in-memory scans, so one authorized user can drive database, memory, and CPU cost upward as farm history grows.
Push filtering and aggregation into SQL, require bounded date ranges or bounded pagination where a full-history result is not essential, and apply a small report-specific concurrency or rate limit keyed by account. Keep exports separate where their product contract genuinely requires a larger data set.
Acceptance criteria
Blocked by
None.
Parent: #244
Epic: #15
Severity: Medium
Execution mode: AFK
What to build
Make every production report path bounded under authenticated but hostile use. Current report generation can load all matching history and perform repeated in-memory scans, so one authorized user can drive database, memory, and CPU cost upward as farm history grows.
Push filtering and aggregation into SQL, require bounded date ranges or bounded pagination where a full-history result is not essential, and apply a small report-specific concurrency or rate limit keyed by account. Keep exports separate where their product contract genuinely requires a larger data set.
Acceptance criteria
Blocked by
None.