Escaping the Wildcard — Java Bug Hunt
Inspired by the search boxes of the world: a user searches for the literal text 50% and gets every row containing "50", because % is a LIKE wildcard.
- Language: Java
- Layer: Database
- Difficulty: Medium
- Concepts: SQL, Escaping
- Modelled on: Search boxes
- Visible tests: a percent sign is literal; an underscore is literal; plain terms still search normally
- Reward: 50 XP for a complete fix
Briefing
Inspired by the search boxes of the world: a user searches for the literal text 50% and gets every row containing "50", because % is a LIKE wildcard. Underscores are worse — a_c matches "abc". User input must be escaped before it goes anywhere near a pattern.
The LIKE matcher (locked) supports \\ escapes. SearchQuery.java doesn't use them.
Bug report
BUG-LIKE50 · Priority: Medium (data leak adjacent) · Reported by: search
contains(text, term) — true iff text contains the LITERAL term:
- "%" and "_" in the term must match themselves, not act as wildcards
Observed: searching "50%" returns "50 cents" and "500 units"; searching "a_c" returns "abc".
Logs
[search] term="50%" matched 4,812 rows (expected 3)The code as shipped
SearchQuery.java (editable)
class SearchQuery {
// True iff text contains the literal term.
static boolean contains(String text, String term) {
return LikeMatcher.like(text, "%" + term + "%");
}
}Read-only context: LikeMatcher.java.
Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More Java bug hunts.