{"record":{"id":"9e5a44a68f9049a7","repo":"immich-app/immich","slug":"invalid-backup-name","errorCode":null,"errorMessage":"Invalid backup name!","messagePattern":"Invalid backup name!","errorType":"exception","errorClass":"BadRequestException","httpStatus":400,"severity":"error","filePath":"server/src/services/database-backup.service.ts","lineNumber":274,"sourceCode":"      this.logger.error(`Database Backup Failure: ${error}`);\n      pgdump?.destroy();\n      gzip?.destroy();\n      await this.storageRepository\n        .unlink(temporaryFilePath)\n\n        .catch((error) => this.logger.error(`Failed to delete failed backup file: ${error}`));\n      throw error;\n    }\n\n    this.logger.log(`Database Backup Success`);\n    return backupFilePath;\n  }\n\n  async uploadBackup(file: Express.Multer.File): Promise<void> {\n    const backupsFolder = StorageCore.getBaseFolder(StorageFolder.Backups);\n    const fn = basename(file.originalname);\n    if (!isValidDatabaseBackupName(fn)) {\n      throw new BadRequestException('Invalid backup name!');\n    }\n\n    const filePath = path.join(backupsFolder, `uploaded-${fn}`);\n    await this.storageRepository.createOrOverwriteFile(filePath, file.buffer);\n  }\n\n  downloadBackup(fileName: string): ImmichFileResponse {\n    if (!isValidDatabaseBackupName(fileName)) {\n      throw new BadRequestException('Invalid backup name!');\n    }\n\n    const filePath = path.join(StorageCore.getBaseFolder(StorageFolder.Backups), fileName);\n\n    return {\n      path: filePath,\n      fileName,\n      cacheControl: CacheControl.PrivateWithoutCache,\n      contentType: fileName.endsWith('.gz') ? 'application/gzip' : 'application/sql',","sourceCodeStart":256,"sourceCodeEnd":292,"githubUrl":"https://github.com/immich-app/immich/blob/e55ac299a4ec7cb372e35dbf2c6c05ee9ce77f6c/server/src/services/database-backup.service.ts#L256-L292","documentation":"`uploadBackup` takes the basename of the uploaded file and validates it against isValidDatabaseBackupName() before writing it into the backups folder. Files whose names don't match the expected backup filename pattern are rejected with this BadRequestException to prevent arbitrary files being written.","triggerScenarios":"Uploading a database backup via POST /api/backups with a file whose originalname doesn't match the immich backup naming pattern (e.g. 'dump.sql', 'my backup.gz', or a name with path components).","commonSituations":"Renaming a pg_dump output before upload; uploading a plain SQL dump instead of the Immich-generated backup file; browser altering the filename; attempting to upload a non-backup file through the endpoint.","solutions":["Rename the file to match the expected Immich backup name pattern (as produced by the built-in backup feature) before uploading.","Download an existing backup from the server to see the exact naming convention and mimic it.","Verify you are uploading the database backup file actually created by Immich, not an arbitrary SQL dump."],"exampleFix":"// before\nformData.append('file', new Blob([data]), 'dump.sql'); // invalid name → 400\n// after\nformData.append('file', new Blob([data]), 'immich-db-backup-20260915.sql.gz'); // matches valid pattern","handlingStrategy":"validation","validationCode":"// Validate the filename against the backup pattern before upload\nconst pattern = /^immich-db-backup-.+$/; // match server's isValidDatabaseBackupName\nif (!pattern.test(basename(file.name))) {\n  file = new File([buffer], `immich-db-backup-${file.name}`, { type: file.type });\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Upload only backups produced/downloaded via Immich's own backup feature.","Keep the server-generated filename intact when moving files between hosts.","Compare against an existing valid backup's name to learn the required pattern."],"tags":["backup","filename-validation","bad-request","upload"],"backgroundTag":"invalid-identifier-format","analyzedSha":"e55ac299a4ec7cb372e35dbf2c6c05ee9ce77f6c","analyzedAt":"2026-09-15T07:20:19.675Z","contentChangedAt":"2026-09-15T07:20:19.675Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}