{"record":{"id":"6942a1367a47bde5","repo":"Mintplex-Labs/anything-llm","slug":"username-must-be-at-least-2-characters","errorCode":null,"errorMessage":"Username must be at least 2 characters","messagePattern":"Username must be at least 2 characters","errorType":"validation","errorClass":null,"httpStatus":400,"severity":"error","filePath":"server/models/user.js","lineNumber":41,"sourceCode":"    \"role\",\n    \"suspended\",\n    \"dailyMessageLimit\",\n    \"bio\",\n  ],\n  validations: {\n    /**\n     * Unix-style username regex:\n     * - Must start with a lowercase letter\n     * - Can contain lowercase letters, digits, underscores, hyphens, @ signs, and periods\n     * - 2-64 characters long\n     */\n    username: (newValue = \"\") => {\n      try {\n        const username = String(newValue);\n        if (username.length > 64)\n          throw new Error(\"Username cannot be longer than 64 characters\");\n        if (username.length < 2)\n          throw new Error(\"Username must be at least 2 characters\");\n        if (!User.usernameRegex.test(username))\n          throw new Error(\n            \"Username must start with a lowercase letter and only contain lowercase letters, numbers, underscores, hyphens, and periods\"\n          );\n        return username;\n      } catch (e) {\n        throw new Error(e.message);\n      }\n    },\n    role: (role = \"default\") => {\n      const VALID_ROLES = [\"default\", \"admin\", \"manager\"];\n      if (!VALID_ROLES.includes(role)) {\n        throw new Error(\n          `Invalid role. Allowed roles are: ${VALID_ROLES.join(\", \")}`\n        );\n      }\n      return String(role);\n    },","sourceCodeStart":23,"sourceCodeEnd":59,"githubUrl":"https://github.com/Mintplex-Labs/anything-llm/blob/3aec848f2885144aa8f1e53b9731a04310d5d558/server/models/user.js#L23-L59","documentation":"Thrown by the username validator in the User model when User.create or User.update receives a username shorter than 2 characters after String() coercion. The check runs before any Prisma write, so the whole operation is rejected as a validation failure. The validator's argument defaults to \"\", so explicitly sending username: \"\" (or undefined through create) also triggers it. Note that User.update skips username validation when the value equals the current username, so this only fires when the username is genuinely being changed to a too-short value (or on create).","triggerScenarios":"Calling User.create({ username: \"k\" }) or user.update(userId, { username: \"\" }); an admin POST/PATCH to the user endpoints with an empty or single-character username; a seed script generating 1-character usernames; a form that submits the key with an empty string instead of omitting it.","commonSituations":"Frontend forms without minlength enforcement or trimming; SSO/LDAP provisioning that maps a 1-character attribute to username; import scripts that derive usernames from truncated email prefixes; API clients that always send every field, including empty ones.","solutions":["Send a username of 2-64 characters that starts with a lowercase letter","Add client-side validation (minlength=2 plus trim) before submitting the create/update request","If the username is unchanged, omit the key from the update payload instead of sending an empty string","For programmatic callers, assert String(username).length >= 2 before calling User.create/User.update"],"exampleFix":"// before\nawait User.create({ username: \"j\", password: passwordHash });\n\n// after\nawait User.create({ username: \"jo\", password: passwordHash });","handlingStrategy":"validation","validationCode":"function isValidUsername(username) {\n  const u = String(username ?? \"\");\n  return u.length >= 2 && u.length <= 64 && /^[a-z][a-z0-9._@-]*$/.test(u);\n}\n\n// before User.create / User.update\nif (!isValidUsername(input.username)) {\n  return res.status(400).json({ error: \"Username must be 2-64 chars, starting with a lowercase letter\" });\n}","typeGuard":null,"tryCatchPattern":"try {\n  const { user, message } = await User.create({ username, password });\n} catch (e) {\n  if (e.message.startsWith(\"Username\")) return res.status(400).json({ error: e.message });\n  throw e;\n}","preventionTips":["Enforce minlength=2 plus trim in the client form","Omit the username key entirely when it is not being changed; never send an empty string","For SSO/LDAP sync, validate generated usernames against the same regex before calling create"],"tags":["validation","username","user-management","string-length"],"backgroundTag":"username-validation-failed","analyzedSha":"3aec848f2885144aa8f1e53b9731a04310d5d558","analyzedAt":"2026-08-18T10:02:21.017Z","contentChangedAt":"2026-08-18T10:02:21.017Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}