Skip to content

Plain text queries with raw double quotes silently produce wrong results or an opaque 422 #149

Description

@shouze

Parent epic: #146

Context and problem

Plain text (non-regex) queries containing raw double quotes produce either silent false positives or an opaque GitHub 422 error, with no local validation before the API call.

Reproduction A, false positives: github-code-search '"react": ' --org fulll returns 666 files and 1000 matches with obvious false positives such as react-native.config.js and plain react imports.

Reproduction B, 422 error: github-code-search '"react": "' --org fulll fails with a fatal query parsing error. This also happens when attempting to escape quotes at the shell level, because the shell consumes the backslash before the program receives it, so the argv ends up identical to reproduction B in both attempts.

Root cause

GitHub's query language strips unescaped balanced quotes and treats adjacent punctuation as separate terms. An odd number of unescaped quotes is rejected by the API with a fatal parsing error. The CLI never validates quote balance before sending the query.

Solution

  • Add a pure validation function that detects an odd number of unescaped double quotes in the user query, excluding an already detected regex token.
  • When detected, the CLI must stop before calling the GitHub API, with a clear message and a corrected example using the proper double escaping for shell and GitHub.
  • Do not touch queries with an even number of quotes, existing behavior for legitimate exact phrase queries must remain unchanged.

Acceptance criteria

  • The command from reproduction B fails locally with an explicit message before any network call, no more raw 422.
  • A legitimate two-quote phrase query keeps working unchanged.
  • The error message includes a corrected example command for searching a literal quote character.

Definition of done

  • bun test passes, including a new unit test for the validation function covering even, odd and no-quote cases
  • bun run lint, bun run format:check, bun run knip pass
  • bun run build.ts compiles
  • Manual validation of reproductions A and B above using the compiled binary

Files

  • github-code-search.ts
  • src/regex.ts, or a new pure helper, to be decided during implementation

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions