bug: search queries with &, #, or + return wrong results — URL params not encoded
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 78/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Quiet
- Tech stack
- typescript
- Domain
- api
Research direction
Start in packages/api/src/EmbeddedChatApi.ts at getSearchMessages and review the URL construction in getUserStatus, userInfo, and userData. Verify the behavior with values containing &, #, and +; done means these values reach the API as the intended search text, user ID, or username rather than altering the query.
Written by the indexing model from the issue text.
Description
Searching for anything with &, #, or + in it returns wrong results or nothing at all.
getSearchMessages in EmbeddedChatApi.ts (line 1124) builds the URL with a template literal:
`${this.host}/api/v1/chat.search?roomId=${this.rid}&searchText=${text}`
The text param goes straight into the URL without encoding. So:
hello & goodbye— the&starts a new query param. Server receivessearchText=helloand a straygoodbyeparam#channel— the#is treated as a URL fragment.searchTextarrives as an empty stringhello world+test— the+is read as a space. Server getshello world test
Same pattern in three other methods:
getUserStatus(line 1236) —userId=${reqUserId}userInfo(line 1253) —userId=${reqUserId}userData(line 1270) —username=${username}
The userId ones are less likely to hit this in practice since IDs are usually alphanumeric, but usernames with special characters would break userData.
File: packages/api/src/EmbeddedChatApi.ts
- Dominant language
- JavaScript
- Stars
- 167
- Forks
- 382
- PR merge metrics
- No merged PRs in 30d
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- No contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from RocketChat/EmbeddedChat
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
RocketChat/EmbeddedChat#1373 ·
-
enhancement
Difficulty 1/5 Under an hour Newbie friendliness 84/100
RocketChat/EmbeddedChat#1360 · 1 comment ·
-
Permissions change-detection in useFetchChatData is dead — applyPermissions re-runs on every callOpen
Difficulty 1/5 Under an hour Newbie friendliness 85/100
RocketChat/EmbeddedChat#1317 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
RocketChat/EmbeddedChat#1315 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
RocketChat/EmbeddedChat#1313 ·
All issues in RocketChat/EmbeddedChat
Similar issues
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
keyxmakerx/Chronicle#967 ·
Maintainers usually reply within 1 day
-
good first issue hacktoberfest
Difficulty 1/5 Under an hour Newbie friendliness 92/100
RogueAlg0/taken#386 · 3 comments ·
Maintainers usually reply within 1 day
-
external-issue to-triage
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
LearningCircuit/local-deep-research#7067 ·
Maintainers usually reply within 1 day