Skip to content

[Due for payment 2026-08-21] [Search] Contextual search sends workspace/room name verbatim as an ID when the name contains a comma #96767

Description

@twisterdotcom

Problem

Opening search from a chat (cmd+K) seeds the chat's scope, e.g. type:expense workspace:Acme,Inc. When the workspace or room name contains a comma (or any character sanitizeSearchValue doesn't quote), submitting sends the literal name to the server as a policyID instead of resolving it to the real ID. The search silently returns "Nothing to show" with no error.

Found by @mukhrr during review of #96448 (out of scope for that PR — splitting out per @twisterdotcom).

Steps to reproduce

  1. Rename any workspace to Acme,Inc — comma, no space.
  2. Open that workspace's expense chat and press cmd+K → input seeds type:expense workspace:Acme,Inc, unquoted.
  3. Press Enter.
  4. Result: "Nothing to show", no error.

Expected vs actual

Expected — submitting resolves the name to the report/policy ID:

input:  type:expense workspace:Acme,Inc
URL:    /search?q=type:expense … policyID:26BE5C4005E188DB
result: that workspace's expenses

Actual — the name is submitted verbatim as an ID:

input:  type:expense workspace:Acme,Inc      ← unquoted
URL:    /search?q=type:expense … policyID:Acme,Inc   ← literal name, not the ID
result: "Nothing to show"                     ← no error

Root cause

getContextualSearchQuery runs the name through sanitizeSearchValue, but getContextualSearchAutocompleteKey builds the substitution key from the raw name. sanitizeSearchValue only quotes on a space or NBSP — so a comma stays unquoted, the parser splits the value on it, the parsed value no longer equals the key, the substitution is skipped, and getUpdatedFilterValue doesn't normalize in:/policyID:. The literal string goes to the server.

The line-break case is the one #96448 makes worse: the query is normalized with lineBreaksToSpaces but the key is not, so they can't match.

Proposed solution

Make the substitution key and the sanitized query agree on the same normalization so lookup succeeds regardless of the character in the name:

  • Apply the same transform (sanitizeSearchValue + lineBreaksToSpaces) to both the query value and the autocomplete key before comparison, or
  • Broaden sanitizeSearchValue to quote on any character the parser treats as a delimiter (comma, etc.), not only space/NBSP.

Either way, getUpdatedFilterValue should resolve workspace:/in: to a policyID:/reportID: rather than passing an unresolved literal to the server.

Open questions

  • Preferred fix location — widen sanitizeSearchValue quoting vs. normalize the key at comparison time? Widening quoting is the more general fix but touches every caller of sanitizeSearchValue.
  • Should an unresolved name fall back to a clear empty-state/error rather than a silent "Nothing to show"?

Related

Issue OwnerCurrent Issue Owner: @parasharrajat

Activity

  1. mukhrr commented on Jul 22, 2026

    @mukhrr
    Contributor

    Commenting to be assigned

  2. mukhrr commented on Aug 10, 2026

    @mukhrr
    Contributor

    2. input seeds type:expense workspace:Acme,Inc

    @twisterdotcom can you update reproduction steps as follow since pre-populating input on CMD+K was rejected in #96448 (comment)

    1. Create a workspace named "Acme, Inc"
    2. Open that workspace's chat
    3. Press cmd+K or Search icon on top right
    4. Click first option: "Search in [your username]'s expenses"

    Actual result: search populates type:expense workspace:Acme, Inc (expense is quoted, Acme, Inc is UNquoted) and hitting enter -> Result: "Nothing to show", no error.

    Expected result: search populates type:expense workspace:Acme, Inc (both quoted) and hitting enter shows result from Acme, Inc workspace

  3. melvin-bot commented on Aug 10, 2026

    @melvin-bot

    Triggered auto assignment to @Julesssss, see https://stackoverflow.com/c/expensify/questions/7972 for more details.

  4. added a commit that references this issue on Aug 11, 2026
    478b36a
  5. mukhrr commented on Aug 11, 2026

    @mukhrr
    Contributor

    @Julesssss are you sure to close before payment? Or did I miss something?

  6. Julesssss commented on Aug 12, 2026

    @Julesssss
    Contributor

    are you sure to close before payment? Or did I miss something?

    Ah this closed automatically after I merged the PR.

  7. 4 remaining items

  8. melvin-bot commented on Aug 14, 2026

    @melvin-bot

    @Julesssss @mukhrr

    The solution for this issue has been 🚀 deployed to production 🚀 in version 9.4.53-10 and is now subject to a 7-day regression period 📆. Here is the list of pull requests that resolve this issue:

    If no regressions arise, payment will be issued on 2026-08-21. 🎊

    The following checklist (instructions) will need to be completed before the issue can be closed. Please copy/paste the BugZero Checklist from here into a new comment on this GH and complete it. If you have the K2 extension, you can simply click: [this button]. If no checklist is needed for this issue, you can click: [no checklist button]

  9. melvin-bot commented on Aug 17, 2026

    @melvin-bot

    @mukhrr Whoops! This issue is 2 days overdue. Let's get this updated quick!

  10. melvin-bot commented on Aug 19, 2026

    @melvin-bot

    @mukhrr Huh... This is 4 days overdue. Who can take care of this?

  11. added
    Awaiting PaymentAuto-added when associated PR is deployed to production
    and removed on Aug 19, 2026
  12. melvin-bot commented on Aug 20, 2026

    @melvin-bot

    Triggered auto assignment to @mallenexpensify (Awaiting Payment)

  13. melvin-bot commented on Aug 20, 2026

    @melvin-bot

    Payment Summary

    Resolving PRs:

    BugZero Checklist (@mallenexpensify)

    • I have confirmed assignees, roles, and Upwork contracts look correct
    • I have paid out Upwork contracts / manual NewDot requests
    • [BugZero Assignee] I have created a GH issue for creating/updating the regression test once above steps have been agreed upon
  14. mallenexpensify commented on Aug 21, 2026

    @mallenexpensify
    Contributor

    Payment Summary

    Contributor: @mukhrr due $250 via NewDot
    Contributor+: @parasharrajat due $250 via NewDot

    @mukhrr plz complete the BZ checklist and tag me in a post once you have. Thx

  15. mukhrr commented on Aug 22, 2026

    @mukhrr
    Contributor

    @mukhrr plz complete the BZ checklist and tag me in a post once you have. Thx

    @mallenexpensify you mean @parasharrajat ?

  16. parasharrajat commented on Aug 22, 2026

    @parasharrajat
    Member

    BugZero Checklist:

    • [Contributor] The offending PR and associated issue have been commented on, pointing out the bug it caused and why, so the author and reviewers can learn from the mistake.

      Link to the comment on the PR: Couldn't figure out. It might be existed from the initial implementation
      Link to the comment on the Issue:

    • [Contributor] If the regression was CRITICAL (e.g. interrupts a core flow) A discussion in #expensify-open-source has been started about whether any other steps should be taken (e.g. updating the PR review checklist) in order to catch this type of bug sooner.

      Link to discussion:

    • [Contributor] If it was decided to create a regression test for the bug, please propose the regression test steps using the template below to ensure the same bug will not reach production again.

    • [BugZero Assignee] Create a GH issue for creating/updating the regression test once above steps have been agreed upon.

      Link to issue: https://github.com/Expensify/Expensify/issues/674862

    Regression Test Proposal

    Test:

    1. Create a workspace named "Acme, Inc"
    2. Open that workspace's chat
    3. Press cmd+K or Search icon on top right
    4. Click first option: "Search in [your username]'s expenses"
    5. Verify type:expense workspace:Acme,Inc quoted.
    6. Type something and hit enter
    7. Verify you see results from Acme, Inc. workspace

    Do we agree 👍 or 👎

    Zapier Logs Run ID: 00040eee-96f2-a04b-9d66-632f0dd1ad74
  17. flaviadefaria commented on Sep 2, 2026

    @flaviadefaria
    Contributor

    Approved: @mukhrr due $250 via NewDot

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

Awaiting PaymentAuto-added when associated PR is deployed to productionDailyKSv2ReviewingHas a PR in review

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions