[PR #7271] [WIP] Fix search wildcard character escaping in transaction quick search #25663

Open
opened 2026-04-16 18:45:56 -05:00 by GiteaMirror · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/actualbudget/actual/pull/7271
Author: @qianchongyang
Created: 3/23/2026
Status: 🔄 Open

Base: masterHead: bounty/20260324-actualbudget-actual-5840


📝 Commits (2)

  • ae3c641 fix: escape special characters in quick search to prevent wildcards
  • f9d6110 [autofix.ci] apply automated fixes

📊 Changes

3 files changed (+44 additions, -10 deletions)

View changed files

📝 packages/desktop-client/src/queries/index.ts (+13 -5)
📝 packages/loot-core/src/platform/server/sqlite/unicodeLike.test.ts (+21 -0)
📝 packages/loot-core/src/platform/server/sqlite/unicodeLike.ts (+10 -5)

📄 Description

Problem

Searching for "?" in the transaction quick search matches all transactions instead of only those with "?" in the note field. The question mark is treated as a query wildcard character and is not properly escaped.

Solution

Added proper escaping for special search characters like "?" and "*" before executing the search query. These characters are now treated as literal characters rather than wildcard operators.

Validation

-- Search for "?"
-- Before: Matches all transactions
-- After: Only transactions with "?" in note field

Fixes #5840


Bundle Stats

Bundle Files count Total bundle size % Changed
desktop-client 27 12.09 MB → 12.09 MB (+169 B) +0.00%
loot-core 1 4.83 MB → 4.83 MB (+121 B) +0.00%
api 4 4.06 MB → 4.06 MB (+119 B) +0.00%
cli 1 7.88 MB 0%
View detailed bundle stats

desktop-client

Total

Files count Total bundle size % Changed
27 12.09 MB → 12.09 MB (+169 B) +0.00%
Changeset
File Δ Size
src/queries/index.ts 📈 +169 B (+7.92%) 2.08 kB → 2.25 kB
View detailed bundle breakdown

Added
No assets were added

Removed
No assets were removed

Bigger

Asset File Size % Changed
static/js/useTransactionBatchActions.js 4.29 MB → 4.29 MB (+169 B) +0.00%

Smaller
No assets were smaller

Unchanged

Asset File Size % Changed
static/js/index.js 3.23 MB 0%
static/js/BackgroundImage.js 119.98 kB 0%
static/js/FormulaEditor.js 846.44 kB 0%
static/js/ReportRouter.js 1.02 MB 0%
static/js/TransactionList.js 81.29 kB 0%
static/js/ca.js 185.57 kB 0%
static/js/da.js 104.66 kB 0%
static/js/de.js 177.58 kB 0%
static/js/en-GB.js 7.16 kB 0%
static/js/en.js 170.68 kB 0%
static/js/es.js 172.13 kB 0%
static/js/fr.js 177.57 kB 0%
static/js/indexeddb-main-thread-worker-e59fee74.js 13.46 kB 0%
static/js/it.js 168.97 kB 0%
static/js/narrow.js 354.27 kB 0%
static/js/nb-NO.js 154.72 kB 0%
static/js/nl.js 111.58 kB 0%
static/js/pl.js 88.34 kB 0%
static/js/pt-BR.js 180.5 kB 0%
static/js/resize-observer.js 18.03 kB 0%
static/js/sv.js 80.58 kB 0%
static/js/th.js 179.94 kB 0%
static/js/theme.js 30.68 kB 0%
static/js/uk.js 213.14 kB 0%
static/js/wide.js 418 B 0%
static/js/workbox-window.prod.es5.js 7.28 kB 0%

loot-core

Total

Files count Total bundle size % Changed
1 4.83 MB → 4.83 MB (+121 B) +0.00%
Changeset
File Δ Size
home/runner/work/actual/actual/packages/loot-core/src/platform/server/sqlite/unicodeLike.ts 📈 +121 B (+22.04%) 549 B → 670 B
View detailed bundle breakdown

Added

Asset File Size % Changed
kcab.worker.CFOVE1uD.js 0 B → 4.83 MB (+4.83 MB) -

Removed

Asset File Size % Changed
kcab.worker.C5hAEdn7.js 4.83 MB → 0 B (-4.83 MB) -100%

Bigger
No assets were bigger

Smaller
No assets were smaller

Unchanged
No assets were unchanged


api

Total

Files count Total bundle size % Changed
4 4.06 MB → 4.06 MB (+119 B) +0.00%
Changeset
File Δ Size
home/runner/work/actual/actual/packages/loot-core/src/platform/server/sqlite/unicodeLike.ts 📈 +119 B (+21.76%) 547 B → 666 B
View detailed bundle breakdown

Added
No assets were added

Removed
No assets were removed

Bigger

Asset File Size % Changed
index.js 3.84 MB → 3.84 MB (+119 B) +0.00%

Smaller
No assets were smaller

Unchanged

Asset File Size % Changed
from-Bl-Hslp4.js 167.73 kB 0%
multipart-parser-BnDysoMr.js 8.1 kB 0%
src-iMkUmuwR.js 43.64 kB 0%

cli

Total

Files count Total bundle size % Changed
1 7.88 MB 0%
View detailed bundle breakdown

Added
No assets were added

Removed
No assets were removed

Bigger
No assets were bigger

Smaller
No assets were smaller

Unchanged

Asset File Size % Changed
cli.js 7.88 MB 0%

🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/actualbudget/actual/pull/7271 **Author:** [@qianchongyang](https://github.com/qianchongyang) **Created:** 3/23/2026 **Status:** 🔄 Open **Base:** `master` ← **Head:** `bounty/20260324-actualbudget-actual-5840` --- ### 📝 Commits (2) - [`ae3c641`](https://github.com/actualbudget/actual/commit/ae3c641a1a11518823438cd0b9ee35a1c21cdf16) fix: escape special characters in quick search to prevent wildcards - [`f9d6110`](https://github.com/actualbudget/actual/commit/f9d6110e9cc60c79401c9577fbe5ce2a0c34185b) [autofix.ci] apply automated fixes ### 📊 Changes **3 files changed** (+44 additions, -10 deletions) <details> <summary>View changed files</summary> 📝 `packages/desktop-client/src/queries/index.ts` (+13 -5) 📝 `packages/loot-core/src/platform/server/sqlite/unicodeLike.test.ts` (+21 -0) 📝 `packages/loot-core/src/platform/server/sqlite/unicodeLike.ts` (+10 -5) </details> ### 📄 Description ## Problem Searching for "?" in the transaction quick search matches all transactions instead of only those with "?" in the note field. The question mark is treated as a query wildcard character and is not properly escaped. ## Solution Added proper escaping for special search characters like "?" and "*" before executing the search query. These characters are now treated as literal characters rather than wildcard operators. ## Validation ```sql -- Search for "?" -- Before: Matches all transactions -- After: Only transactions with "?" in note field ``` Fixes #5840 <!--- actual-bot-sections ---> <hr /> <!--- bundlestats-action-comment key:combined start ---> ### Bundle Stats Bundle | Files count | Total bundle size | % Changed ------ | ----------- | ----------------- | --------- desktop-client | 27 | 12.09 MB → 12.09 MB (+169 B) | +0.00% loot-core | 1 | 4.83 MB → 4.83 MB (+121 B) | +0.00% api | 4 | 4.06 MB → 4.06 MB (+119 B) | +0.00% cli | 1 | 7.88 MB | 0% <details> <summary>View detailed bundle stats</summary> #### desktop-client **Total** Files count | Total bundle size | % Changed ----------- | ----------------- | --------- 27 | 12.09 MB → 12.09 MB (+169 B) | +0.00% <details> <summary>Changeset</summary> File | Δ | Size ---- | - | ---- `src/queries/index.ts` | 📈 +169 B (+7.92%) | 2.08 kB → 2.25 kB </details> <details> <summary>View detailed bundle breakdown</summary> <div> **Added** No assets were added **Removed** No assets were removed **Bigger** Asset | File Size | % Changed ----- | --------- | --------- static/js/useTransactionBatchActions.js | 4.29 MB → 4.29 MB (+169 B) | +0.00% **Smaller** No assets were smaller **Unchanged** Asset | File Size | % Changed ----- | --------- | --------- static/js/index.js | 3.23 MB | 0% static/js/BackgroundImage.js | 119.98 kB | 0% static/js/FormulaEditor.js | 846.44 kB | 0% static/js/ReportRouter.js | 1.02 MB | 0% static/js/TransactionList.js | 81.29 kB | 0% static/js/ca.js | 185.57 kB | 0% static/js/da.js | 104.66 kB | 0% static/js/de.js | 177.58 kB | 0% static/js/en-GB.js | 7.16 kB | 0% static/js/en.js | 170.68 kB | 0% static/js/es.js | 172.13 kB | 0% static/js/fr.js | 177.57 kB | 0% static/js/indexeddb-main-thread-worker-e59fee74.js | 13.46 kB | 0% static/js/it.js | 168.97 kB | 0% static/js/narrow.js | 354.27 kB | 0% static/js/nb-NO.js | 154.72 kB | 0% static/js/nl.js | 111.58 kB | 0% static/js/pl.js | 88.34 kB | 0% static/js/pt-BR.js | 180.5 kB | 0% static/js/resize-observer.js | 18.03 kB | 0% static/js/sv.js | 80.58 kB | 0% static/js/th.js | 179.94 kB | 0% static/js/theme.js | 30.68 kB | 0% static/js/uk.js | 213.14 kB | 0% static/js/wide.js | 418 B | 0% static/js/workbox-window.prod.es5.js | 7.28 kB | 0% </div> </details> --- #### loot-core **Total** Files count | Total bundle size | % Changed ----------- | ----------------- | --------- 1 | 4.83 MB → 4.83 MB (+121 B) | +0.00% <details> <summary>Changeset</summary> File | Δ | Size ---- | - | ---- `home/runner/work/actual/actual/packages/loot-core/src/platform/server/sqlite/unicodeLike.ts` | 📈 +121 B (+22.04%) | 549 B → 670 B </details> <details> <summary>View detailed bundle breakdown</summary> <div> **Added** Asset | File Size | % Changed ----- | --------- | --------- kcab.worker.CFOVE1uD.js | 0 B → 4.83 MB (+4.83 MB) | - **Removed** Asset | File Size | % Changed ----- | --------- | --------- kcab.worker.C5hAEdn7.js | 4.83 MB → 0 B (-4.83 MB) | -100% **Bigger** No assets were bigger **Smaller** No assets were smaller **Unchanged** No assets were unchanged </div> </details> --- #### api **Total** Files count | Total bundle size | % Changed ----------- | ----------------- | --------- 4 | 4.06 MB → 4.06 MB (+119 B) | +0.00% <details> <summary>Changeset</summary> File | Δ | Size ---- | - | ---- `home/runner/work/actual/actual/packages/loot-core/src/platform/server/sqlite/unicodeLike.ts` | 📈 +119 B (+21.76%) | 547 B → 666 B </details> <details> <summary>View detailed bundle breakdown</summary> <div> **Added** No assets were added **Removed** No assets were removed **Bigger** Asset | File Size | % Changed ----- | --------- | --------- index.js | 3.84 MB → 3.84 MB (+119 B) | +0.00% **Smaller** No assets were smaller **Unchanged** Asset | File Size | % Changed ----- | --------- | --------- from-Bl-Hslp4.js | 167.73 kB | 0% multipart-parser-BnDysoMr.js | 8.1 kB | 0% src-iMkUmuwR.js | 43.64 kB | 0% </div> </details> --- #### cli **Total** Files count | Total bundle size | % Changed ----------- | ----------------- | --------- 1 | 7.88 MB | 0% <details> <summary>View detailed bundle breakdown</summary> <div> **Added** No assets were added **Removed** No assets were removed **Bigger** No assets were bigger **Smaller** No assets were smaller **Unchanged** Asset | File Size | % Changed ----- | --------- | --------- cli.js | 7.88 MB | 0% </div> </details> </details> <!--- bundlestats-action-comment key:combined end ---> --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
GiteaMirror added the pull-request label 2026-04-16 18:45:56 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/actual#25663