Hint 3 Take a look at the SearchRepository where the injection takes place. The parameter is in between %. To shortcut the query you can do this %'; --