# \[RUBY\] : elasticsearch-ruby : Special characters not escaped by the library

**URL:** <https://discuss.elastic.co/t/ruby-elasticsearch-ruby-special-characters-not-escaped-by-the-library/15187>\
**Category:** Elasticsearch\
**Created:** [January 10, 2014, 12:34am UTC](https://discuss.elastic.co/t/ruby-elasticsearch-ruby-special-characters-not-escaped-by-the-library/15187 "2014-01-10T00:34:31Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Srirang\_Doddihal](https://avatars.discourse-cdn.com/v4/letter/s/f4b2a3/32.png) [@Srirang\_Doddihal](https://discuss.elastic.co/u/Srirang_Doddihal)\
**Post date:** [January 10, 2014, 12:34am UTC](https://discuss.elastic.co/t/ruby-elasticsearch-ruby-special-characters-not-escaped-by-the-library/15187/1 "2014-01-10T00:34:31Z")

</div>

Hi,

I tried out the elasticsearch Ruby gem today and found that it does not  
escape the reserve characters when searching with the query\_string query.

As a library providing easy to use search API, wouldn't it be better if the  
library escaped the reserve characters in this case?  
The API can support a flag, with a sensible default value, to enable or  
disable this escaping behavior.

Or is it an explicit design decision that the users themselves have to  
escape the reserve characters before sending it to this library?

I am using v0.4.5.

Regards,  
Brahmana

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/0bc324f1-dc81-4640-aea0-1a3b08663f20%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/0bc324f1-dc81-4640-aea0-1a3b08663f20%40googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Jason\_Wee](https://avatars.discourse-cdn.com/v4/letter/j/7ea924/32.png) [@Jason\_Wee](https://discuss.elastic.co/u/Jason_Wee)\
**Post date:** [January 10, 2014, 10:13am UTC](https://discuss.elastic.co/t/ruby-elasticsearch-ruby-special-characters-not-escaped-by-the-library/15187/2 "2014-01-10T10:13:29Z")

</div>

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

imho, || could means OR or literary as it is. So if the library escape for  
you, when you mean || to OR, that's wrong.

hth

Jason

On Fri, Jan 10, 2014 at 8:34 AM, Srirang Doddihal [om.brahmana@gmail.com](mailto:om.brahmana@gmail.com)wrote:

> Hi,
> 
> I tried out the elasticsearch Ruby gem today and found that it does not  
> escape the reserve characters when searching with the query\_string query.
> 
> As a library providing easy to use search API, wouldn't it be better if  
> the library escaped the reserve characters in this case?  
> The API can support a flag, with a sensible default value, to enable or  
> disable this escaping behavior.
> 
> Or is it an explicit design decision that the users themselves have to  
> escape the reserve characters before sending it to this library?
> 
> I am using v0.4.5.
> 
> Regards,  
> Brahmana
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/0bc324f1-dc81-4640-aea0-1a3b08663f20%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/0bc324f1-dc81-4640-aea0-1a3b08663f20%40googlegroups.com)  
> .  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAHO4itzMkB6Jv0EkfiXSB7528EPVN4Zwtp96bs5Of93mk%2BRnFg%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAHO4itzMkB6Jv0EkfiXSB7528EPVN4Zwtp96bs5Of93mk%2BRnFg%40mail.gmail.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Srirang\_Doddihal](https://avatars.discourse-cdn.com/v4/letter/s/f4b2a3/32.png) [@Srirang\_Doddihal](https://discuss.elastic.co/u/Srirang_Doddihal)\
**Post date:** [January 29, 2014, 5:19am UTC](https://discuss.elastic.co/t/ruby-elasticsearch-ruby-special-characters-not-escaped-by-the-library/15187/3 "2014-01-29T05:19:26Z")

</div>

Sorry for the delayed response.

On Fri, Jan 10, 2014 at 3:43 PM, Jason Wee [peichieh@gmail.com](mailto:peichieh@gmail.com) wrote:

> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html#_reserved_characters)

imho, || could means OR or literary as it is. So if the library escape for

> you, when you mean || to OR, that's wrong.

Makes sense. However a character like " (double quote - when used like :  
40" tv) will make elasticsearch fail outright with the message saying that  
it was unable to parse the query.

Wrong search happening is somewhat ok and can be considered as user not  
knowing how to use those operators, but an explicit error is a much worse  
user behaviour, isn't it?

Could the library add some such query string sanitize feature?

> hth
> 
> Jason
> 
> On Fri, Jan 10, 2014 at 8:34 AM, Srirang Doddihal [om.brahmana@gmail.com](mailto:om.brahmana@gmail.com)wrote:
> 
> > Hi,
> > 
> > I tried out the elasticsearch Ruby gem today and found that it does not  
> > escape the reserve characters when searching with the query\_string query.
> > 
> > As a library providing easy to use search API, wouldn't it be better if  
> > the library escaped the reserve characters in this case?  
> > The API can support a flag, with a sensible default value, to enable or  
> > disable this escaping behavior.
> > 
> > Or is it an explicit design decision that the users themselves have to  
> > escape the reserve characters before sending it to this library?
> > 
> > I am using v0.4.5.
> > 
> > Regards,  
> > Brahmana
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).
> > 
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/0bc324f1-dc81-4640-aea0-1a3b08663f20%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/0bc324f1-dc81-4640-aea0-1a3b08663f20%40googlegroups.com)  
> > .  
> > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> You received this message because you are subscribed to a topic in the  
> Google Groups "elasticsearch" group.  
> To unsubscribe from this topic, visit  
> [https://groups.google.com/d/topic/elasticsearch/QsVgeOywOkk/unsubscribe](https://groups.google.com/d/topic/elasticsearch/QsVgeOywOkk/unsubscribe).  
> To unsubscribe from this group and all its topics, send an email to  
> [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/CAHO4itzMkB6Jv0EkfiXSB7528EPVN4Zwtp96bs5Of93mk%2BRnFg%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAHO4itzMkB6Jv0EkfiXSB7528EPVN4Zwtp96bs5Of93mk%2BRnFg%40mail.gmail.com)  
> .
> 
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
Regards,  
Srirang G Doddihal  
Brahmana.

The LIGHT shows the way.  
The WISE see it.  
The BRAVE walk it.  
The PERSISTENT endure and complete it.

I want to do it all ALONE.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CACBGNLt6OkUdEFN%2BFffc-AxfrrbV-2%3Difq5uWMQ1c0h3KsEgbw%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CACBGNLt6OkUdEFN%2BFffc-AxfrrbV-2%3Difq5uWMQ1c0h3KsEgbw%40mail.gmail.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![karmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karmi/32/44951_2.png) [@karmi](https://discuss.elastic.co/u/karmi)\
**Post date:** [January 29, 2014, 10:15am UTC](https://discuss.elastic.co/t/ruby-elasticsearch-ruby-special-characters-not-escaped-by-the-library/15187/4 "2014-01-29T10:15:35Z")

</div>

The `elasticsearch-ruby` library is what we call a "low level" client,  
closely matching the semantics and notation of the REST API.

So, you pass in exactly the same query as you would into Curl. The only  
exception here are e.g. names of document types, which are part of the URL,  
and are correctly escaped for you.

Finally, as Jason notes below, no library can "intelligently escape"  
special characters for you, because sometimes, `~` is a `~` and sometimes  
it's a proximity search expression...

Have a look at  
the [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/query-dsl-simple-query-string-query.html)  
which might provide a better syntax, and generally avoid the `query_string`  
query for user facing searches, unless warranted by a special use case  
(librarians, researchers, etc).

Karel

On Friday, January 10, 2014 1:34:31 AM UTC+1, Srirang Doddihal wrote:

> Hi,
> 
> I tried out the elasticsearch Ruby gem today and found that it does not  
> escape the reserve characters when searching with the query\_string query.
> 
> As a library providing easy to use search API, wouldn't it be better if  
> the library escaped the reserve characters in this case?  
> The API can support a flag, with a sensible default value, to enable or  
> disable this escaping behavior.
> 
> Or is it an explicit design decision that the users themselves have to  
> escape the reserve characters before sending it to this library?
> 
> I am using v0.4.5.
> 
> Regards,  
> Brahmana

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/85308030-d0bb-4982-bb32-7424ba0068fe%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/85308030-d0bb-4982-bb32-7424ba0068fe%40googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Srirang\_Doddihal](https://avatars.discourse-cdn.com/v4/letter/s/f4b2a3/32.png) [@Srirang\_Doddihal](https://discuss.elastic.co/u/Srirang_Doddihal)\
**Post date:** [January 31, 2014, 3:05pm UTC](https://discuss.elastic.co/t/ruby-elasticsearch-ruby-special-characters-not-escaped-by-the-library/15187/5 "2014-01-31T15:05:03Z")

</div>

Yeah, I agree. It probably is best to keep the ruby library API same as the  
server ReST API. If elasticsearch server wants it to be escaped, that's  
what this Ruby library expects. Makes sense.

Thank you.

On Wed, Jan 29, 2014 at 3:45 PM, Karel Minařík [karel.minarik@gmail.com](mailto:karel.minarik@gmail.com)wrote:

> The `elasticsearch-ruby` library is what we call a "low level" client,  
> closely matching the semantics and notation of the REST API.
> 
> So, you pass in exactly the same query as you would into Curl. The only  
> exception here are e.g. names of document types, which are part of the URL,  
> and are correctly escaped for you.
> 
> Finally, as Jason notes below, no library can "intelligently escape"  
> special characters for you, because sometimes, `~` is a `~` and sometimes  
> it's a proximity search expression...
> 
> Have a look at the  
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/query-dsl-simple-query-string-query.htmlwhich) might provide a better syntax, and generally avoid the `query_string`  
> query for user facing searches, unless warranted by a special use case  
> (librarians, researchers, etc).
> 
> Karel
> 
> On Friday, January 10, 2014 1:34:31 AM UTC+1, Srirang Doddihal wrote:
> 
> > Hi,
> > 
> > I tried out the elasticsearch Ruby gem today and found that it does not  
> > escape the reserve characters when searching with the query\_string query.
> > 
> > As a library providing easy to use search API, wouldn't it be better if  
> > the library escaped the reserve characters in this case?  
> > The API can support a flag, with a sensible default value, to enable or  
> > disable this escaping behavior.
> > 
> > Or is it an explicit design decision that the users themselves have to  
> > escape the reserve characters before sending it to this library?
> > 
> > I am using v0.4.5.
> > 
> > Regards,  
> > Brahmana
> 
> --  
> You received this message because you are subscribed to a topic in the  
> Google Groups "elasticsearch" group.  
> To unsubscribe from this topic, visit  
> [https://groups.google.com/d/topic/elasticsearch/QsVgeOywOkk/unsubscribe](https://groups.google.com/d/topic/elasticsearch/QsVgeOywOkk/unsubscribe).  
> To unsubscribe from this group and all its topics, send an email to  
> [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/85308030-d0bb-4982-bb32-7424ba0068fe%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/85308030-d0bb-4982-bb32-7424ba0068fe%40googlegroups.com)  
> .
> 
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
Regards,  
Srirang G Doddihal  
Brahmana.

The LIGHT shows the way.  
The WISE see it.  
The BRAVE walk it.  
The PERSISTENT endure and complete it.

I want to do it all ALONE.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CACBGNLt\_fsy0fsiyYvPjQRsCW740E9oDto%2BBXpiDSbn9QpXFRw%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CACBGNLt_fsy0fsiyYvPjQRsCW740E9oDto%2BBXpiDSbn9QpXFRw%40mail.gmail.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:53am UTC](https://discuss.elastic.co/t/ruby-elasticsearch-ruby-special-characters-not-escaped-by-the-library/15187/6 "2017-07-06T01:53:41Z")

</div>


