Bug Description
The admin user search in src/modules/admin/admin-users.service.ts (lines 37-44) has the same LIKE pattern escaping vulnerability as the course search. User input is directly interpolated into ilike patterns without escaping special characters.
Location
src/modules/admin/admin-users.service.ts lines 37-44
const conditions = search
? [
or(
ilike(users.stellarAddress, `%${search}%`),
ilike(users.displayName, `%${search}%`),
)!,
]
: [];
The Problem
If an admin searches for % or _:
% matches any sequence of characters (returns all users)
_ matches any single character
This allows:
- Bypassing intended search filtering
- Crafting expensive LIKE scans on large user tables
Recommended Fix
function escapeLikePattern(pattern: string): string {
return pattern.replace(/[%_]/g, '\\$&');
}
const conditions = search
? [
or(
ilike(users.stellarAddress, `%${escapeLikePattern(search)}%`),
ilike(users.displayName, `%${escapeLikePattern(search)}%`),
)!,
]
: [];
Acceptance Criteria
- Escape LIKE pattern characters in admin user search
- Apply the same fix to all
ilike queries across the codebase
- Add a shared utility function for LIKE pattern escaping
Severity
low - Admin-only endpoint, but should still follow best practices.
Bug Description
The admin user search in
src/modules/admin/admin-users.service.ts(lines 37-44) has the same LIKE pattern escaping vulnerability as the course search. User input is directly interpolated intoilikepatterns without escaping special characters.Location
src/modules/admin/admin-users.service.tslines 37-44The Problem
If an admin searches for
%or_:%matches any sequence of characters (returns all users)_matches any single characterThis allows:
Recommended Fix
Acceptance Criteria
ilikequeries across the codebaseSeverity
low - Admin-only endpoint, but should still follow best practices.