Repository navigation
[Due for payment 2026-08-21] [Search] Contextual search sends workspace/room name verbatim as an ID when the name contains a comma #96767
Description
Activity
Commenting to be assigned
- addedReviewingHas a PR in reviewHas a PR in reviewWeeklyKSv2KSv2and removedWeeklyKSv2KSv2
on Jul 27, 2026 2. input seeds
type:expense workspace:Acme,Inc@twisterdotcom can you update reproduction steps as follow since pre-populating input on CMD+K was rejected in #96448 (comment)
- Create a workspace named "Acme, Inc"
- Open that workspace's chat
- Press cmd+K or Search icon on top right
- Click first option: "Search in [your username]'s expenses"
Actual result: search populates
type:expense workspace:Acme, Inc(expense is quoted, Acme, Inc is UNquoted) and hitting enter -> Result: "Nothing to show", no error.Expected result: search populates
type:expense workspace:Acme, Inc(both quoted) and hitting enter shows result from Acme, Inc workspaceTriggered auto assignment to @Julesssss, see https://stackoverflow.com/c/expensify/questions/7972 for more details.
- added a commit that references this issue
on Aug 11, 2026 @Julesssss are you sure to close before payment? Or did I miss something?
are you sure to close before payment? Or did I miss something?
Ah this closed automatically after I merged the PR.
4 remaining items
The solution for this issue has been 🚀 deployed to production 🚀 in version 9.4.53-10 and is now subject to a 7-day regression period 📆. Here is the list of pull requests that resolve this issue:
If no regressions arise, payment will be issued on 2026-08-21. 🎊
The following checklist (instructions) will need to be completed before the issue can be closed. Please copy/paste the BugZero Checklist from here into a new comment on this GH and complete it. If you have the K2 extension, you can simply click: [this button]. If no checklist is needed for this issue, you can click: [no checklist button]
@mukhrr Whoops! This issue is 2 days overdue. Let's get this updated quick!
@mukhrr Huh... This is 4 days overdue. Who can take care of this?
- addedAwaiting PaymentAuto-added when associated PR is deployed to productionAuto-added when associated PR is deployed to productionand removed
on Aug 19, 2026 Triggered auto assignment to @mallenexpensify (
Awaiting Payment)Payment Summary
Resolving PRs:
-
Reviewer: @mukhrr owed $250 via NewDot
BugZero Checklist (@mallenexpensify)
- I have confirmed assignees, roles, and Upwork contracts look correct
- I have paid out Upwork contracts / manual NewDot requests
- [BugZero Assignee] I have created a GH issue for creating/updating the regression test once above steps have been agreed upon
Payment Summary
Contributor: @mukhrr due $250 via NewDot
Contributor+: @parasharrajat due $250 via NewDot@mukhrr plz complete the BZ checklist and tag me in a post once you have. Thx
@mukhrr plz complete the BZ checklist and tag me in a post once you have. Thx
@mallenexpensify you mean @parasharrajat ?
Reacted by Matt AllenBugZero Checklist:
-
[Contributor] The offending PR and associated issue have been commented on, pointing out the bug it caused and why, so the author and reviewers can learn from the mistake.
Link to the comment on the PR: Couldn't figure out. It might be existed from the initial implementation
Link to the comment on the Issue: -
[Contributor] If the regression was CRITICAL (e.g. interrupts a core flow) A discussion in #expensify-open-source has been started about whether any other steps should be taken (e.g. updating the PR review checklist) in order to catch this type of bug sooner.
Link to discussion:
-
[Contributor] If it was decided to create a regression test for the bug, please propose the regression test steps using the template below to ensure the same bug will not reach production again.
-
[BugZero Assignee] Create a GH issue for creating/updating the regression test once above steps have been agreed upon.
Link to issue: https://github.com/Expensify/Expensify/issues/674862
Regression Test Proposal
Test:
- Create a workspace named "Acme, Inc"
- Open that workspace's chat
- Press cmd+K or Search icon on top right
- Click first option: "Search in [your username]'s expenses"
- Verify type:expense workspace:Acme,Inc quoted.
- Type something and hit enter
- Verify you see results from Acme, Inc. workspace
Do we agree 👍 or 👎
Zapier Logs
Run ID: 00040eee-96f2-a04b-9d66-632f0dd1ad74Reacted by Matt Allen-
Approved: @mukhrr due $250 via NewDot
Problem
Opening search from a chat (cmd+K) seeds the chat's scope, e.g.
type:expense workspace:Acme,Inc. When the workspace or room name contains a comma (or any charactersanitizeSearchValuedoesn't quote), submitting sends the literal name to the server as apolicyIDinstead of resolving it to the real ID. The search silently returns "Nothing to show" with no error.Found by @mukhrr during review of #96448 (out of scope for that PR — splitting out per @twisterdotcom).
Steps to reproduce
Acme,Inc— comma, no space.type:expense workspace:Acme,Inc, unquoted.Expected vs actual
Expected — submitting resolves the name to the report/policy ID:
Actual — the name is submitted verbatim as an ID:
Root cause
getContextualSearchQueryruns the name throughsanitizeSearchValue, butgetContextualSearchAutocompleteKeybuilds the substitution key from the raw name.sanitizeSearchValueonly quotes on a space or NBSP — so a comma stays unquoted, the parser splits the value on it, the parsed value no longer equals the key, the substitution is skipped, andgetUpdatedFilterValuedoesn't normalizein:/policyID:. The literal string goes to the server.The line-break case is the one #96448 makes worse: the query is normalized with
lineBreaksToSpacesbut the key is not, so they can't match.Proposed solution
Make the substitution key and the sanitized query agree on the same normalization so lookup succeeds regardless of the character in the name:
sanitizeSearchValue+lineBreaksToSpaces) to both the query value and the autocomplete key before comparison, orsanitizeSearchValueto quote on any character the parser treats as a delimiter (comma, etc.), not only space/NBSP.Either way,
getUpdatedFilterValueshould resolveworkspace:/in:to apolicyID:/reportID:rather than passing an unresolved literal to the server.Open questions
sanitizeSearchValuequoting vs. normalize the key at comparison time? Widening quoting is the more general fix but touches every caller ofsanitizeSearchValue.Related
Issue Owner
Current Issue Owner: @parasharrajat