Skip to content

fix(search): sanitize fts query operators#178

Open
RerankerGuo wants to merge 1 commit into
TencentCloud:mainfrom
RerankerGuo:fix/fts-query-operator-sanitization
Open

fix(search): sanitize fts query operators#178
RerankerGuo wants to merge 1 commit into
TencentCloud:mainfrom
RerankerGuo:fix/fts-query-operator-sanitization

Conversation

@RerankerGuo

Copy link
Copy Markdown

Description | 描述

Strip FTS5 boolean/proximity operators from raw search text before tokenization so user input cannot carry query syntax into the
generated MATCH expression.

Related Issue | 关联 Issue

Fix #160

Change Type | 修改类型

  • Bug fix | Bug 修复
  • New feature | 新功能
  • Documentation update | 文档更新
  • Code optimization | 代码优化

Self-test Checklist | 自测清单

  • Verified locally | 本地验证通过
  • No existing features affected | 无影响现有功能

Additional Notes | 其他说明

Verified with npm test and npm run build using Node v24.15.0.

Signed-off-by: Ziyang Guo <121015044+RerankerGuo@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(search): buildFtsQuery does not sanitize FTS5 operators — user input alters query semantics

1 participant