{"record":{"id":"68bdbd1c0b881b50","repo":"Mintplex-Labs/anything-llm","slug":"key-cannot-start-with-user","errorCode":null,"errorMessage":"Key cannot start with 'user.'","messagePattern":"Key cannot start with 'user\\.'","errorType":"validation","errorClass":null,"httpStatus":500,"severity":"warning","filePath":"server/models/systemPromptVariables.js","lineNumber":365,"sourceCode":"    }\n  },\n\n  /**\n   * Internal function to check if a variable key is valid\n   * @param {string} key\n   * @param {boolean} checkExisting\n   * @returns {Promise<boolean>}\n   */\n  _checkVariableKey: async function (key = null, checkExisting = true) {\n    if (!key) throw new Error(\"Key is required\");\n    if (typeof key !== \"string\") throw new Error(\"Key must be a string\");\n    if (!/^[a-zA-Z0-9_]+$/.test(key))\n      throw new Error(\"Key must contain only letters, numbers and underscores\");\n    if (key.length > 255)\n      throw new Error(\"Key must be less than 255 characters\");\n    if (key.length < 3) throw new Error(\"Key must be at least 3 characters\");\n    if (key.startsWith(\"user.\"))\n      throw new Error(\"Key cannot start with 'user.'\");\n    if (key.startsWith(\"system.\"))\n      throw new Error(\"Key cannot start with 'system.'\");\n    if (checkExisting && (await this.get(key)) !== null)\n      throw new Error(\"System prompt variable with this key already exists\");\n\n    return true;\n  },\n};\n\nmodule.exports = { SystemPromptVariables };\n","sourceCodeStart":347,"sourceCodeEnd":376,"githubUrl":"https://github.com/Mintplex-Labs/anything-llm/blob/3aec848f2885144aa8f1e53b9731a04310d5d558/server/models/systemPromptVariables.js#L347-L376","documentation":"Keys starting with 'user.' are reserved: the variable expansion engine maps user.* placeholders to per-user properties, so custom variables may not shadow that namespace. Note that any key containing a dot already fails the earlier character-set check, so in the current validation order this guard is defense-in-depth for the reserved namespace and rarely the first error a dotted key produces.","triggerScenarios":"Attempting to create a key like 'user.name' or 'user.email' to override per-user expansion; copying a template placeholder ({{user.username}}) verbatim as a custom variable key.","commonSituations":"Users trying to customize per-user prompt behavior by defining their own user.* variables; importing variable sets from other prompt systems that use dotted namespaces.","solutions":["Choose a key outside the reserved namespace, e.g. 'current_username' instead of 'user.username'","Rely on the built-in user.* expansion for per-user values rather than defining custom ones","If you need namespacing, separate with underscores which the character check permits"],"exampleFix":"// before\nSystemPromptVariables.create({ key: 'user.timezone', value: 'UTC' }); // reserved prefix (and dot fails character check)\n\n// after\nSystemPromptVariables.create({ key: 'default_timezone', value: 'UTC' });","handlingStrategy":"validation","validationCode":"const RESERVED_PREFIXES = ['user.', 'system.'];\n\nfunction usesReservedPrefix(key) {\n  return typeof key === 'string' && RESERVED_PREFIXES.some((p) => key.startsWith(p));\n}\n\nif (usesReservedPrefix(key)) {\n  return res.status(400).json({ error: 'Keys may not start with user. or system.' });\n}","typeGuard":null,"tryCatchPattern":"try {\n  await SystemPromptVariables.create({ key, value });\n} catch (err) {\n  if (/cannot start with/.test(err.message)) {\n    return res.status(400).json({ error: 'Reserved namespace; rename the key' });\n  }\n  throw err;\n}","preventionTips":["Keep a documented list of reserved prefixes and check against it in UI validation","Use underscores, not dots, for any pseudo-namespacing in keys","Rely on built-in user.* expansion for per-user values instead of redefining them"],"tags":["system-prompt","validation","reserved-name"],"backgroundTag":"reserved-keyword-conflict","analyzedSha":"3aec848f2885144aa8f1e53b9731a04310d5d558","analyzedAt":"2026-08-18T10:02:21.017Z","contentChangedAt":"2026-08-18T10:02:21.017Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}