fix(phase2c): add input validation and security hardening for PR review master
Addresses critical P0 PR review issues for Phase 2C metadata hydration: Input Validation (user_repo.go): - Add MaxBatchSize constant (1000 DIDs) to prevent excessive queries - Validate batch size before database operations - Validate DID format (must start with "did:") - Prevents SQL injection and malformed queries Security Hardening (comment_service.go): - Add HTTPS validation for community avatar URLs - Validate CID format (must start with "baf" for IPFS CIDv1) - Add URL escaping with url.QueryEscape() for DID and CID parameters - Import "net/url" for proper URL handling - Prevents mixed content warnings, MitM attacks, and injection attacks API Documentation (interfaces.go): - Add comprehensive godoc for GetByDIDs method - Document parameters, return values, and behavior - Include usage examples for developers All changes maintain backward compatibility while adding critical security and validation layers. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com>