Steps
On a DB graph with a tag Project, blocks tagged #Project, and a query block {{query (tags [[Project]])}} made with /query (Tags filter, Project) on the page "Gremlin Home", on the web app:
- Open the tag page "Project".
- Click the page title, press End, type
" and press Escape. The tag is now named Project".
- Open "Gremlin Home".
Expected
The query still lists the blocks tagged with the renamed tag. The query was never edited, and it stores the tag by reference.
Actual
The query block shows the error box "Query error: Report issue" with the text (tags [[Project"]]). The console shows {:renderer-query-failed {:kind :dsl, :error #error {:message "Unmatched delimiter ]." ...}}} from frontend.worker.handler.render-resource.query, and use-query-result rethrows it in render.
The steps reproduced it 3 of 3 times (Playwright, trusted input, a new graph each time).
Cause (read in code)
frontend.components.block/query-result takes the DSL string from the query block's title as the renderer receives it, where the tag appears by its current title ((tags [[Project"]])), and the worker parses that string again. logseq.db.frontend.query-dsl/pre-transform (deps/db/src/logseq/db/frontend/query_dsl.cljs) turns each page reference into an EDN string with
(string/replace s #"\"(?:\\.|[^\"\\])*\"|\[\[(.*?)\]\]" quoted-page-ref)
and quoted-page-ref puts the title between double quotes without escaping it. A " in the title ends that string early, a \ starts an escape, and a title containing ]] or [[ is cut at the first ]]. The reader then fails with "Unmatched delimiter", "Unsupported escape character" or "Invalid character". The app accepts all of these characters in a tag's title, so a rename breaks queries the user never touched.
Found by a monkey test (gremlins.js with trusted Playwright input): 22 of 401 runs ended in "Query error" boxes because the query did not parse (21 reader errors, 1 "Doesn't support name"). In all 22 the query text is the seeded (tags [[...]]) with the tag's title changed from Project, for example to Project[[Gremlin Garden]], [[Gremlin Home]], Project]] or \. In the 5 runs whose actions I read, the tag had been renamed on its page and the query block was not edited.
The steps above fail 3 of 3 times on the web build of master 16c4ed1a0.
Steps
On a DB graph with a tag
Project, blocks tagged#Project, and a query block{{query (tags [[Project]])}}made with/query(Tags filter, Project) on the page "Gremlin Home", on the web app:"and press Escape. The tag is now namedProject".Expected
The query still lists the blocks tagged with the renamed tag. The query was never edited, and it stores the tag by reference.
Actual
The query block shows the error box "Query error: Report issue" with the text
(tags [[Project"]]). The console shows{:renderer-query-failed {:kind :dsl, :error #error {:message "Unmatched delimiter ]." ...}}}fromfrontend.worker.handler.render-resource.query, anduse-query-resultrethrows it in render.The steps reproduced it 3 of 3 times (Playwright, trusted input, a new graph each time).
Cause (read in code)
frontend.components.block/query-resulttakes the DSL string from the query block's title as the renderer receives it, where the tag appears by its current title ((tags [[Project"]])), and the worker parses that string again.logseq.db.frontend.query-dsl/pre-transform(deps/db/src/logseq/db/frontend/query_dsl.cljs) turns each page reference into an EDN string withand
quoted-page-refputs the title between double quotes without escaping it. A"in the title ends that string early, a\starts an escape, and a title containing]]or[[is cut at the first]]. The reader then fails with "Unmatched delimiter", "Unsupported escape character" or "Invalid character". The app accepts all of these characters in a tag's title, so a rename breaks queries the user never touched.Found by a monkey test (gremlins.js with trusted Playwright input): 22 of 401 runs ended in "Query error" boxes because the query did not parse (21 reader errors, 1 "Doesn't support name"). In all 22 the query text is the seeded
(tags [[...]])with the tag's title changed fromProject, for example toProject[[Gremlin Garden]],[[Gremlin Home]],Project]]or\. In the 5 runs whose actions I read, the tag had been renamed on its page and the query block was not edited.The steps above fail 3 of 3 times on the web build of master
16c4ed1a0.