What are approaches to you prevent DoS attacks with such an architecture? It seems trivial for an attacker to generate super expensive queries en masse.
Strict row limits could bring some relief but don't solve the problem.
I bet there are solutions for this but it's not very obvious. Would someone briefly explain?