Why nothing you type can change the query

Your words and filter values are only ever data, checked on the phone and again on Opensolr.

Whatever you type, and whatever a filter value contains, it is only ever data. The shape of every search is fixed in the app, and Opensolr checks it again before it reaches your index.

01 · On the phone
  • Your text travels only in one bound parameter, uq, which the search reads as a value. It is never pasted into the query, so braces, colons or quotes are just characters.
  • Every filter value travels the same way, as a bound value of a terms filter. A word with + or - in front becomes its own bound value too.
  • The page size is held between 1 and 1,000, and the starting point can never be negative.
  • Every search is a POST over HTTPS: a request body keeps what you searched for out of address bars and access logs.
  • Browsing, its counts and the tag suggestions never leave the phone, so for those there is no request at all.
02 · On Opensolr's side

A search by meaning goes through photos_select, which runs it only on your own photos index. Before it does, it refuses any parameter that could send the request elsewhere or change what Solr does with it: a vector of the phone's own, the response format, the request handler, shards, streaming, commits, and joins that would read another index. The vector is made there and never leaves.

The full list of what the app sends is in photos_select. The rest of the app's safeguards are in the security model.

Finding photos

Opensolr Photos is open source and MIT licensed. Questions about your Opensolr account, index or plan go to opensolr.com/contact; questions about the app itself belong on GitHub.

Opensolr Photos Documentation