Commit b8e19c4
authored
Handle empty and FTS5-operator search queries without raising a 500 (#481)
* Handle empty and FTS5-operator search queries without raising a 500
Two adjacent crashes on the public book search path, both reachable via
`?search=`:
- A query that sanitizes down to nothing (e.g. `^$`, an emoji, `!!!`, a
bare `"`) made `matches_for_highlight` return nil, so the highlight
helper hit `nil.map`. Return an empty match set instead, which renders
as normal un-highlighted content.
- Bare FTS5 boolean operators (`OR`, `AND`, `NOT`, `NEAR`, ...) survived
character sanitization and reached SQLite as an FTS5 syntax error.
Rebuild the query from its balanced quoted phrases and bare words,
quoting every token as a string literal so arbitrary input is matched
literally instead of parsed as FTS5 syntax. This also subsumes the old
unbalanced-quote handling.
Ordinary term and phrase searches are unaffected.
* Escape highlight terms so punctuated phrase matches don't raise
FTS5 highlight() spans can include document punctuation, so a phrase match
against content like "alpha(beta" hands the highlight helper a term
containing regex metacharacters. Interpolating it straight into
/\b...\b/ raised a RegexpError (e.g. `?search=alpha_beta` on a page
containing "alpha(beta"), breaking the page render. Regexp.escape the term
so it is matched literally.
* Address review: path helpers, response-body assertion, fixture reuse, empty-quote phrase boundary
- Use book_search_path / leaves(:welcome_section) fixture / assert_in_body in
the new search tests to match the repo's testing conventions.
- quote_query_tokens: consume empty quote pairs in place so a stray "" no
longer shifts a following phrase's quote boundaries and splits it into
separate word matches; drop empty tokens.
* Scrub invalid UTF-8 before sanitizing search queries
String#gsub raises ArgumentError on invalid byte sequences, so a malformed
query string could raise in sanitize_query_syntax. Rails rejects malformed
request encoding with a 400 before either search controller runs, so this was
not reachable as a 500 over HTTP — but scrubbing keeps the shared search sink
total for every caller.
* Trim breadcrumby commentary from the search changes
Drop the change-narrating comments on the scrub call, the highlight-term
escaping, and the new tests; the code and test names carry the intent. Keep
the quote_query_tokens comment, which documents non-obvious FTS5 behavior.1 parent 96a6c71 commit b8e19c4
6 files changed
Lines changed: 121 additions & 9 deletions
File tree
- app
- helpers
- models/leaf
- test
- controllers
- books
- helpers
- models/leaf
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
23 | 23 | | |
24 | 24 | | |
25 | 25 | | |
26 | | - | |
| 26 | + | |
27 | 27 | | |
28 | 28 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
15 | 15 | | |
16 | 16 | | |
17 | 17 | | |
18 | | - | |
| 18 | + | |
19 | 19 | | |
20 | | - | |
| 20 | + | |
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
| |||
50 | 50 | | |
51 | 51 | | |
52 | 52 | | |
| 53 | + | |
| 54 | + | |
53 | 55 | | |
54 | 56 | | |
55 | 57 | | |
| |||
106 | 108 | | |
107 | 109 | | |
108 | 110 | | |
109 | | - | |
110 | | - | |
111 | | - | |
112 | | - | |
113 | | - | |
114 | | - | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
115 | 127 | | |
116 | 128 | | |
117 | 129 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
41 | 41 | | |
42 | 42 | | |
43 | 43 | | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
44 | 59 | | |
45 | 60 | | |
46 | 61 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
30 | 30 | | |
31 | 31 | | |
32 | 32 | | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
33 | 71 | | |
34 | 72 | | |
35 | 73 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | 3 | | |
| 4 | + | |
| 5 | + | |
4 | 6 | | |
5 | 7 | | |
6 | 8 | | |
| |||
16 | 18 | | |
17 | 19 | | |
18 | 20 | | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
19 | 31 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
38 | 38 | | |
39 | 39 | | |
40 | 40 | | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
41 | 76 | | |
42 | 77 | | |
43 | 78 | | |
| |||
0 commit comments