Skip to content

Escape LIKE patterns in admin user search #533

Description

@DeFiVC

Bug Description

The admin user search in src/modules/admin/admin-users.service.ts (lines 37-44) has the same LIKE pattern escaping vulnerability as the course search. User input is directly interpolated into ilike patterns without escaping special characters.

Location

src/modules/admin/admin-users.service.ts lines 37-44

const conditions = search
    ? [
          or(
              ilike(users.stellarAddress, `%${search}%`),
              ilike(users.displayName, `%${search}%`),
          )!,
      ]
    : [];

The Problem

If an admin searches for % or _:

  • % matches any sequence of characters (returns all users)
  • _ matches any single character

This allows:

  1. Bypassing intended search filtering
  2. Crafting expensive LIKE scans on large user tables

Recommended Fix

function escapeLikePattern(pattern: string): string {
    return pattern.replace(/[%_]/g, '\\$&');
}

const conditions = search
    ? [
          or(
              ilike(users.stellarAddress, `%${escapeLikePattern(search)}%`),
              ilike(users.displayName, `%${escapeLikePattern(search)}%`),
          )!,
      ]
    : [];

Acceptance Criteria

  • Escape LIKE pattern characters in admin user search
  • Apply the same fix to all ilike queries across the codebase
  • Add a shared utility function for LIKE pattern escaping

Severity

low - Admin-only endpoint, but should still follow best practices.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions