Mintplex-Labs/anything-llm · error
Invalid folder name.
Error message
Invalid folder name.
What it means
The flex-UI twin of the API endpoint: POST /document/create-folder (admin/manager role) applies the same normalizePath + isWithin containment check on the folder name and throws 'Invalid folder name.' when the resolved path would leave documentsPath. Caught and returned as HTTP 500 'Failed to create folder: Invalid folder name. '. Same input rules as the API variant: relative names only, no parent traversal, no absolute components.
Solutions
- Enter a plain relative name in the folder dialog ('Client 2024 Invoices'), then create subfolders separately if nesting is needed
- Replace slashes and '..' with separators like '-' when the name originates from a filesystem path
- If you are integrating programmatically, mirror the server rule: reject names that are not strictly relative and parent-free before submitting
Example fix
// before
const name = '/Client 2024/Invoices'; // absolute -> rejected
// after
const name = 'Client 2024 - Invoices'; // relative, separator-free
await api.post('/document/create-folder', { name }); Defensive patterns
Strategy: validation
Validate before calling
function isRelativeSafeName(name) {
return typeof name === 'string' && name.length > 0 && !name.includes('..') && !name.startsWith('/') && !name.startsWith('\\') && !/^[A-Za-z]:/.test(name);
}
if (!isRelativeSafeName(form.value.name)) { showFieldError('Use a plain folder name without slashes or ..'); return; } Type guard
function isSafeFolderName(name: unknown): name is string { return typeof name === 'string' && name.length > 0 && !name.includes('..') && !/[\\/]/.test(name); } Try / catch
try { await createFolder(name); } catch (e) { if (/Invalid folder name/.test(e.message)) { /* fix the input, show user-facing validation, do not re-POST the same value */ } else throw e; } Prevention
- Validate in the form/UI before submit: no slashes, no '..', plain display names
- Convert pasted filesystem paths into flat names (replace separators with '-') at input time
- Watch for the paired 500 'Folder by that name already exists' — the next most common create-folder failure
When it happens
Trigger: Submitting the workspace 'create folder' form with a name containing '../' beyond the strip-able prefix, an absolute path, a Windows drive segment, or a name that normalizes to the documents root itself.
Common situations: Users pasting full paths ('/Client 2024/Invoices') into the folder-name field; copy-pasted names with trailing dots/separators that normalize oddly; automation scripts driving the flex endpoints with unsanitized names.
Understand the failure class
Background: Path traversal blocked: "path escapes the workspace" and "outside site root" errors when a path will not stay inside its allowed directory — this error's family across 26 libraries.
Related errors
- Invalid path name
- Could not find a document by id
- data.message || "Could not update slash command preset."
- data.message || "Error creating slash command preset."
- Failed to create folder
AI-assisted analysis of Mintplex-Labs/anything-llm@3aec848f28 (2026-08-18).
Data as JSON: /api/errors/fcdc44c60e4cc84f.
Report an issue: GitHub.
Appendix: source
Thrown at server/endpoints/document.js:22
const {
flexUserRoleValid,
ROLES,
} = require("../utils/middleware/multiUserProtected");
const { validatedRequest } = require("../utils/middleware/validatedRequest");
const fs = require("fs");
const path = require("path");
function documentEndpoints(app) {
if (!app) return;
app.post(
"/document/create-folder",
[validatedRequest, flexUserRoleValid([ROLES.admin, ROLES.manager])],
async (request, response) => {
try {
const { name } = reqBody(request);
const storagePath = path.join(documentsPath, normalizePath(name));
if (!isWithin(path.resolve(documentsPath), path.resolve(storagePath)))
throw new Error("Invalid folder name.");
if (fs.existsSync(storagePath)) {
response.status(500).json({
success: false,
message: "Folder by that name already exists",
});
return;
}
fs.mkdirSync(storagePath, { recursive: true });
response.status(200).json({ success: true, message: null });
} catch (e) {
console.error(e);
response.status(500).json({
success: false,
message: `Failed to create folder: ${e.message} `,
});
}View on GitHub (pinned to 3aec848f28)