Skip to content

🛡️ fix: Escape People Picker Search Regex - #13169

Merged
danny-avila merged 1 commit into
devfrom
danny-avila/fix-people-picker-regex-redos
May 18, 2026
Merged

danny-avila merged 1 commit into
devfrom
danny-avila/fix-people-picker-regex-redos

Conversation

@danny-avila

Copy link
Copy Markdown
Collaborator

Summary

I fixed the people-picker and shared user search paths so user-supplied search text is treated as literal text before it reaches MongoDB regex queries or relevance scoring.

  • Escaped search terms before building regex filters for users, groups, and roles.
  • Replaced regex-based exact-match scoring with lowercase string comparisons.
  • Validated q on search-principals and stopped returning internal error details on failures.
  • Added regression tests for regex metacharacters, invalid regex syntax, query shape validation, and sanitized error responses.

Change Type

  • Bug fix (non-breaking change which fixes an issue)

Testing

I validated the search fix with focused data-schemas and API controller tests, then ran package builds and lint for the touched files.

Test Configuration:

  • npm run build:data-provider
  • npx jest src/methods/userGroup.spec.ts src/methods/user.methods.spec.ts --runInBand from packages/data-schemas
  • npm run build:data-schemas
  • npm run build:api
  • npx jest server/controllers/__tests__/PermissionsController.spec.js --runInBand from api
  • npx eslint api/server/controllers/PermissionsController.js api/server/controllers/__tests__/PermissionsController.spec.js packages/data-schemas/src/methods/user.ts packages/data-schemas/src/methods/userGroup.ts packages/data-schemas/src/methods/user.methods.spec.ts packages/data-schemas/src/methods/userGroup.spec.ts

Checklist

  • My code adheres to this project's style guidelines
  • I have performed a self-review of my own code
  • My changes do not introduce new warnings
  • I have written tests demonstrating that my changes are effective or that my feature works
  • Local unit tests pass with my changes

Copilot AI review requested due to automatic review settings May 18, 2026 01:37

Copy link
Copy Markdown
Collaborator Author

@codex review

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR hardens the “people picker” / principal search flow by ensuring user-supplied search terms are treated as literal text before being used in MongoDB regex queries or relevance scoring, preventing regex injection and invalid-regex failures.

Changes:

  • Escapes user-provided search strings before constructing MongoDB RegExp filters in data-schemas search methods.
  • Replaces regex-based “exact match” relevance scoring with lowercase string comparisons.
  • Tightens q validation in the API search-principals controller and removes internal error details from 500 responses; adds regression tests.

Reviewed changes

Copilot reviewed 6 out of 6 changed files in this pull request and generated 2 comments.

Show a summary per file
File Description
packages/data-schemas/src/methods/userGroup.ts Escapes regex input for group/user/role queries; switches relevance scoring to literal string comparisons.
packages/data-schemas/src/methods/userGroup.spec.ts Adds regression tests for literal handling of regex metacharacters and invalid regex syntax; updates scoring expectations.
packages/data-schemas/src/methods/user.ts Escapes regex input for user search and replaces exact-regex scoring with literal comparisons.
packages/data-schemas/src/methods/user.methods.spec.ts Adds regression tests ensuring regex metacharacters/invalid patterns are treated literally in user search.
api/server/controllers/PermissionsController.js Validates q type/shape, uses trimmed query consistently, and stops returning internal error details on failures.
api/server/controllers/tests/PermissionsController.spec.js Adds controller tests for non-string q, trimmed literal query behavior, and sanitized 500 responses.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +390 to 391
if (typeof rawQuery !== 'string' || rawQuery.trim().length === 0) {
return res.status(400).json({
Comment on lines 277 to 281
// Score results by relevance
const exactRegex = new RegExp(`^${searchPattern.trim()}$`, 'i');
const startsWithPattern = searchPattern.trim().toLowerCase();
const startsWithPattern = trimmedPattern.toLowerCase();

const scoredUsers = users.map((user) => {
const searchableFields = [user.name, user.email, user.username].filter(
@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Breezy!

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@github-actions

Copy link
Copy Markdown
Contributor

GitNexus: 🚀 deployed

The LibreChat-pr-13169 index is now live on the MCP server.
Deploy run

@danny-avila
danny-avila changed the base branch from main to dev May 18, 2026 12:55
@danny-avila
danny-avila merged commit 89d10a0 into dev May 18, 2026
16 checks passed
@danny-avila
danny-avila deleted the danny-avila/fix-people-picker-regex-redos branch May 18, 2026 13:04
patricia2510 pushed a commit to lexaeon-org/libre-chat that referenced this pull request May 21, 2026
fuuuzzy pushed a commit to fuuuzzy/LibreChat that referenced this pull request May 22, 2026
ThomasVuNguyen pushed a commit to ThomasVuNguyen/LibreChat that referenced this pull request Jul 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants