Mintplex-Labs/anything-llm · error

Invalid folder name.

Error message

Invalid folder name.

What it means

The flex-UI twin of the API endpoint: POST /document/create-folder (admin/manager role) applies the same normalizePath + isWithin containment check on the folder name and throws 'Invalid folder name.' when the resolved path would leave documentsPath. Caught and returned as HTTP 500 'Failed to create folder: Invalid folder name. '. Same input rules as the API variant: relative names only, no parent traversal, no absolute components.

Solutions

  1. Enter a plain relative name in the folder dialog ('Client 2024 Invoices'), then create subfolders separately if nesting is needed
  2. Replace slashes and '..' with separators like '-' when the name originates from a filesystem path
  3. If you are integrating programmatically, mirror the server rule: reject names that are not strictly relative and parent-free before submitting

Example fix

// before
const name = '/Client 2024/Invoices';   // absolute -> rejected
// after
const name = 'Client 2024 - Invoices'; // relative, separator-free
await api.post('/document/create-folder', { name });
Defensive patterns

Strategy: validation

Validate before calling

function isRelativeSafeName(name) {
  return typeof name === 'string' && name.length > 0 && !name.includes('..') && !name.startsWith('/') && !name.startsWith('\\') && !/^[A-Za-z]:/.test(name);
}
if (!isRelativeSafeName(form.value.name)) { showFieldError('Use a plain folder name without slashes or ..'); return; }

Type guard

function isSafeFolderName(name: unknown): name is string { return typeof name === 'string' && name.length > 0 && !name.includes('..') && !/[\\/]/.test(name); }

Try / catch

try { await createFolder(name); } catch (e) { if (/Invalid folder name/.test(e.message)) { /* fix the input, show user-facing validation, do not re-POST the same value */ } else throw e; }

Prevention

When it happens

Trigger: Submitting the workspace 'create folder' form with a name containing '../' beyond the strip-able prefix, an absolute path, a Windows drive segment, or a name that normalizes to the documents root itself.

Common situations: Users pasting full paths ('/Client 2024/Invoices') into the folder-name field; copy-pasted names with trailing dots/separators that normalize oddly; automation scripts driving the flex endpoints with unsanitized names.

Understand the failure class

Background: Path traversal blocked: "path escapes the workspace" and "outside site root" errors when a path will not stay inside its allowed directory — this error's family across 26 libraries.

Related errors


AI-assisted analysis of Mintplex-Labs/anything-llm@3aec848f28 (2026-08-18). Data as JSON: /api/errors/fcdc44c60e4cc84f. Report an issue: GitHub.

Appendix: source

Thrown at server/endpoints/document.js:22

const {
  flexUserRoleValid,
  ROLES,
} = require("../utils/middleware/multiUserProtected");
const { validatedRequest } = require("../utils/middleware/validatedRequest");
const fs = require("fs");
const path = require("path");

function documentEndpoints(app) {
  if (!app) return;
  app.post(
    "/document/create-folder",
    [validatedRequest, flexUserRoleValid([ROLES.admin, ROLES.manager])],
    async (request, response) => {
      try {
        const { name } = reqBody(request);
        const storagePath = path.join(documentsPath, normalizePath(name));
        if (!isWithin(path.resolve(documentsPath), path.resolve(storagePath)))
          throw new Error("Invalid folder name.");

        if (fs.existsSync(storagePath)) {
          response.status(500).json({
            success: false,
            message: "Folder by that name already exists",
          });
          return;
        }

        fs.mkdirSync(storagePath, { recursive: true });
        response.status(200).json({ success: true, message: null });
      } catch (e) {
        console.error(e);
        response.status(500).json({
          success: false,
          message: `Failed to create folder: ${e.message} `,
        });
      }

View on GitHub (pinned to 3aec848f28)