# Limit the flexibility of a query\_string query?

**URL:** <https://discuss.elastic.co/t/limit-the-flexibility-of-a-query-string-query/9975>\
**Category:** Elasticsearch\
**Created:** [December 6, 2012, 5:38pm UTC](https://discuss.elastic.co/t/limit-the-flexibility-of-a-query-string-query/9975 "2012-12-06T17:38:54Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anil\_Rhemtulla](https://avatars.discourse-cdn.com/v4/letter/a/b19c9b/32.png) [@Anil\_Rhemtulla](https://discuss.elastic.co/u/Anil_Rhemtulla)\
**Post date:** [December 6, 2012, 5:38pm UTC](https://discuss.elastic.co/t/limit-the-flexibility-of-a-query-string-query/9975/1 "2012-12-06T17:38:54Z")

</div>

I'd like to take advantage of the query string query to avoid the pain of  
parsing a user's search text. I want them to have pretty much all the  
powers that the parser provides including AND, OR, prefix, fuzzy etc.

However, there are a couple limitations I'd like to impose:

1. No leading wildcard (simple enough, that's an option on query\_string).
2. The user should not be able to choose the fields to search in (e.g.  
"price:100" should not be allowed). Is there a way to do this with ES, or  
do I need to handle restrictions like this on the client end?

Thanks,  
Anil

--

---

<div class="post-metadata">

**Author:** ![Igor\_Motov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_motov/32/45193_2.png) [@Igor\_Motov](https://discuss.elastic.co/u/Igor_Motov)\
**Post date:** [December 7, 2012, 3:04pm UTC](https://discuss.elastic.co/t/limit-the-flexibility-of-a-query-string-query/9975/2 "2012-12-07T15:04:03Z")

</div>

I would suggest writing your own parser. It will pay off in the long run.

On Thursday, December 6, 2012 12:38:54 PM UTC-5, Anil Rhemtulla wrote:

> I'd like to take advantage of the query string query to avoid the pain of  
> parsing a user's search text. I want them to have pretty much all the  
> powers that the parser provides including AND, OR, prefix, fuzzy etc.
> 
> However, there are a couple limitations I'd like to impose:
> 
> 1. No leading wildcard (simple enough, that's an option on query\_string).
> 2. The user should not be able to choose the fields to search in (e.g.  
> "price:100" should not be allowed). Is there a way to do this with ES, or  
> do I need to handle restrictions like this on the client end?
> 
> Thanks,  
> Anil

--

---

<div class="post-metadata">

**Author:** ![maziyar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maziyar/32/18423_2.png) [@maziyar](https://discuss.elastic.co/u/maziyar)\
**Post date:** [May 21, 2017, 10:58pm UTC](https://discuss.elastic.co/t/limit-the-flexibility-of-a-query-string-query/9975/3 "2017-05-21T22:58:39Z")

</div>

Hi,

Not sure what @Anil_Rhemtulla has finally done to overcome this issue, butI have the same problem with query\_string. Very powerful and at the same time very exposed and unrestricted.

I don't believe writing a parser by users is a feasible solution just for limiting the fields at least. Like "flags" in [Simple Query String](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-simple-query-string-query.html#_flags), I think it would be nice to have the option like "allowed fields" in query\_string to not allowing the users to query any fields in your mapping.

Cheers,  
Maziyar

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:00pm UTC](https://discuss.elastic.co/t/limit-the-flexibility-of-a-query-string-query/9975/4 "2017-07-05T22:00:12Z")

</div>


