Home Analyst Portal

Use of square brackets in SEARCH does not return the same results if used in FILTER.

Jason_MeyerJason_Meyer Customer Advanced IT Monkey ✭✭✭

Has anyone else noticed that the use of square brackets in SEARCH does not return the same results if used in FILTER?


If we setup a saved search to look for all Change Requests that have [Nebraska] in the title, the search results include what appears to be all change request work items.

If we setup a filter on the Title Column using that same criteria contains [Nebraska], the results only include work items that have [Nebraska] in the title.


Bug?

Best Answer

Answers

  • Jason_MeyerJason_Meyer Customer Advanced IT Monkey ✭✭✭

    Thanks Justin, issue resolved. 😎

  • Peter_MiklianPeter_Miklian Customer Advanced IT Monkey ✭✭✭

    @Justin_Workman speaking of SQL query in the search: is this input sanitized somehow or could user do some SQL injection attacks? :) Thanks.

  • Justin_WorkmanJustin_Workman Cireson Support Super IT Monkey ✭✭✭✭✭

    @Peter_Miklian - Yes. The input is broken up into parameters that are passed into a stored procedure. The search condition will always be treated as a value to evaluate rather than a statement or piece of a statement to execute.

Sign In or Register to comment.