Use allowlisted filters (--mimes, --exts, --url-pattern, --archive-ids).
Keep --unsafe-where off scripts and never expose it to untrusted input.
Bound dump with --limit and --max-bytes; treat exported files as untrusted content.
Do not open exported payloads automatically.
For phrase search, populate the texts sidecar once
(metawarc index-content --text) and refresh with --rescan after
new WARCs are added. The search backend is a bounded DuckDB columnar
scan over the texts Parquet sidecar — DuckDB's FTS extension
regressed in 1.5.x.
For exports that exceed METAWARC_REQUEST_TIMEOUT_SECONDS (default 30 s),
submit a metawarc jobs submit job instead of polling
GET /records/list. The MVP kind is export-records; the result
lands in <data_dir>/jobs/<job_id>/.
The runner is shared between POST /jobs (HTTP) and metawarc jobs submit (CLI). Submitting from the CLI writes the file immediately;
execution waits for metawarc serve to be running.
Job state is plain JSON in <data_dir>/jobs/. Treat it like a local
cache: monitor doctor and cleanup if you let jobs accumulate.
Use metawarc jobs wait for scripts that should block until a job
finishes; exit codes 0/1/2/3/124 match succeeded / unknown /
cancelled / failed / timeout.