Mintplex-Labs/anything-llm · warning

Username cannot be longer than 64 characters

Error message

Username cannot be longer than 64 characters

What it means

The User model's username validator caps length at 64 characters (the overall regex window is 2-64). Values longer than 64 are rejected before any database write, so this is pure input validation, not a Prisma constraint error.

Solutions

  1. Derive a shorter username (e.g. use the email local part, truncated) instead of the full address
  2. Enforce maxlength=64 plus client-side validation on signup/admin forms
  3. For SSO mappings, add a truncation plus uniqueness suffix step

Example fix

// before
User.create({ username: 'very.long.email.address.2026+tags@extremely-long-domain.example.com', ... });

// after
const username = email.split('@')[0].replace(/[^a-z0-9._-]/g, '').slice(0, 64) || `user_${Date.now()}`;
User.create({ username, ... });
Defensive patterns

Strategy: validation

Validate before calling

const MAX_USERNAME = 64;

if (typeof username !== 'string' || username.length > MAX_USERNAME) {
  return res.status(400).json({ error: `username must be a string of at most ${MAX_USERNAME} characters` });
}

Try / catch

try {
  await User.create({ username, password });
} catch (err) {
  if (/cannot be longer than 64 characters/.test(err.message)) {
    return res.status(400).json({ error: 'Username too long (max 64)' });
  }
  throw err;
}

Prevention

When it happens

Trigger: Programmatic user creation mapping a full email or display name into username; SSO/OAuth payloads with long local parts; concatenated generated names (first.last+suffix@domain) exceeding 64 chars.

Common situations: Directory-sync and SSO provisioning flows; admin bulk-import scripts; seeders using realistic-but-long names.

Related errors


AI-assisted analysis of Mintplex-Labs/anything-llm@3aec848f28 (2026-08-18). Data as JSON: /api/errors/e55718f8715390b8. Report an issue: GitHub.

Appendix: source

Thrown at server/models/user.js:39

    "password",
    "pfpFilename",
    "role",
    "suspended",
    "dailyMessageLimit",
    "bio",
  ],
  validations: {
    /**
     * Unix-style username regex:
     * - Must start with a lowercase letter
     * - Can contain lowercase letters, digits, underscores, hyphens, @ signs, and periods
     * - 2-64 characters long
     */
    username: (newValue = "") => {
      try {
        const username = String(newValue);
        if (username.length > 64)
          throw new Error("Username cannot be longer than 64 characters");
        if (username.length < 2)
          throw new Error("Username must be at least 2 characters");
        if (!User.usernameRegex.test(username))
          throw new Error(
            "Username must start with a lowercase letter and only contain lowercase letters, numbers, underscores, hyphens, and periods"
          );
        return username;
      } catch (e) {
        throw new Error(e.message);
      }
    },
    role: (role = "default") => {
      const VALID_ROLES = ["default", "admin", "manager"];
      if (!VALID_ROLES.includes(role)) {
        throw new Error(
          `Invalid role. Allowed roles are: ${VALID_ROLES.join(", ")}`
        );
      }

View on GitHub (pinned to 3aec848f28)