Escaping the Wildcard — Java Bug Hunt

Inspired by the search boxes of the world: a user searches for the literal text 50% and gets every row containing "50", because % is a LIKE wildcard.

  • Language: Java
  • Layer: Database
  • Difficulty: Medium
  • Concepts: SQL, Escaping
  • Modelled on: Search boxes
  • Visible tests: a percent sign is literal; an underscore is literal; plain terms still search normally
  • Reward: 50 XP for a complete fix

Briefing

Inspired by the search boxes of the world: a user searches for the literal text 50% and gets every row containing "50", because % is a LIKE wildcard. Underscores are worse — a_c matches "abc". User input must be escaped before it goes anywhere near a pattern.

The LIKE matcher (locked) supports \\ escapes. SearchQuery.java doesn't use them.

Bug report

BUG-LIKE50 · Priority: Medium (data leak adjacent) · Reported by: search

contains(text, term) — true iff text contains the LITERAL term:

  • "%" and "_" in the term must match themselves, not act as wildcards

Observed: searching "50%" returns "50 cents" and "500 units"; searching "a_c" returns "abc".

Logs

[search] term="50%" matched 4,812 rows (expected 3)

The code as shipped

SearchQuery.java (editable)

class SearchQuery {
    // True iff text contains the literal term.
    static boolean contains(String text, String term) {
        return LikeMatcher.like(text, "%" + term + "%");
    }
}

Read-only context: LikeMatcher.java.

Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More Java bug hunts.