diff options
| author | syuilo <Syuilotan@yahoo.co.jp> | 2023-01-09 08:46:10 +0900 |
|---|---|---|
| committer | syuilo <Syuilotan@yahoo.co.jp> | 2023-01-09 08:46:10 +0900 |
| commit | 2acb3917ba28df0054a9e347bfba7b58e22d30a9 (patch) | |
| tree | 290a2050f0b2586b236a1a7d167a25358def2e4c /packages/backend/src/server/api/endpoints/notes | |
| parent | :cookie: (diff) | |
| parent | fix: Escape SQL LIKE (#9493) (diff) | |
| download | sharkey-2acb3917ba28df0054a9e347bfba7b58e22d30a9.tar.gz sharkey-2acb3917ba28df0054a9e347bfba7b58e22d30a9.tar.bz2 sharkey-2acb3917ba28df0054a9e347bfba7b58e22d30a9.zip | |
Merge branch 'develop' of https://github.com/misskey-dev/misskey into develop
Diffstat (limited to 'packages/backend/src/server/api/endpoints/notes')
| -rw-r--r-- | packages/backend/src/server/api/endpoints/notes/search.ts | 3 |
1 files changed, 2 insertions, 1 deletions
diff --git a/packages/backend/src/server/api/endpoints/notes/search.ts b/packages/backend/src/server/api/endpoints/notes/search.ts index 27b477e141..02701ffe1e 100644 --- a/packages/backend/src/server/api/endpoints/notes/search.ts +++ b/packages/backend/src/server/api/endpoints/notes/search.ts @@ -6,6 +6,7 @@ import { QueryService } from '@/core/QueryService.js'; import { NoteEntityService } from '@/core/entities/NoteEntityService.js'; import type { Config } from '@/config.js'; import { DI } from '@/di-symbols.js'; +import { sqlLikeEscape } from '@/misc/sql-like-escape'; export const meta = { tags: ['notes'], @@ -70,7 +71,7 @@ export default class extends Endpoint<typeof meta, typeof paramDef> { } query - .andWhere('note.text ILIKE :q', { q: `%${ps.query}%` }) + .andWhere('note.text ILIKE :q', { q: `%${ sqlLikeEscape(ps.query) }%` }) .innerJoinAndSelect('note.user', 'user') .leftJoinAndSelect('user.avatar', 'avatar') .leftJoinAndSelect('user.banner', 'banner') |