{"record":{"id":"ac329deb6ed1d006","repo":"spring-projects/spring-ai","slug":"identifier-s-should-only-contain-alphanumeric-c","errorCode":null,"errorMessage":"Identifier '%s' should only contain alphanumeric characters and underscores","messagePattern":"Identifier '(.+?)' should only contain alphanumeric characters and underscores","errorType":"exception","errorClass":"IllegalArgumentException","httpStatus":null,"severity":"error","filePath":"vector-stores/spring-ai-mariadb-store/src/main/java/org/springframework/ai/vectorstore/mariadb/MariaDBSchemaValidator.java","lineNumber":172,"sourceCode":"\n\t/**\n\t * Escaped identifier according to MariaDB requirement.\n\t * @param identifier identifier\n\t * @param alwaysQuote indicate if identifier must be quoted even if not necessary.\n\t * @return return escaped identifier, quoted when necessary or indicated with\n\t * alwaysQuote.\n\t * @see <a href=\"https://mariadb.com/kb/en/library/identifier-names/\">mariadb\n\t * identifier name</a>\n\t */\n\t// @Override when not supporting java 8\n\tpublic static String validateAndEnquoteIdentifier(String identifier, boolean alwaysQuote) {\n\t\ttry {\n\t\t\tString quotedId = Driver.enquoteIdentifier(identifier, alwaysQuote);\n\t\t\t// force use of simple table name\n\t\t\tif (Pattern.compile(\"`?[\\\\p{Alnum}_]*`?\").matcher(identifier).matches()) {\n\t\t\t\treturn quotedId;\n\t\t\t}\n\t\t\tthrow new IllegalArgumentException(String\n\t\t\t\t.format(\"Identifier '%s' should only contain alphanumeric characters and underscores\", quotedId));\n\t\t}\n\t\tcatch (SQLException e) {\n\t\t\tthrow new IllegalArgumentException(e);\n\t\t}\n\t}\n\n}\n","sourceCodeStart":154,"sourceCodeEnd":181,"githubUrl":"https://github.com/spring-projects/spring-ai/blob/98a7beda4f29d80a71c5837eb4053b03a93a46f7/vector-stores/spring-ai-mariadb-store/src/main/java/org/springframework/ai/vectorstore/mariadb/MariaDBSchemaValidator.java#L154-L181","documentation":"MariaDBSchemaValidator.validateAndEnquoteIdentifier validates schema/table/column identifiers before quoting them in SQL. If an identifier contains characters other than alphanumerics and underscores (after Driver.enquoteIdentifier), it throws this IllegalArgumentException to prevent SQL injection through identifier fields.","triggerScenarios":"Configuring the MariaDB store with a table name, schema name, or field name containing hyphens, dots, spaces, or other special characters — e.g. table-name: 'my-store' — triggers validation during initializeSchema/validateTableSchema.","commonSituations":"Copy-pasting table names with hyphens from other systems, schema names with dots, using reserved characters to try to force quoting, environment-specific naming conventions with dashes.","solutions":["Rename the table/schema/identifiers to contain only [A-Za-z0-9_] characters.","Create a new compliant table and copy data into it.","If the special-character name must be kept, create an underscore-only view/alias and point the store at it."],"exampleFix":"// before\nspring.ai.vectorstore.mariadb.table-name=my-vector-store\n// after\nspring.ai.vectorstore.mariadb.table-name=my_vector_store","handlingStrategy":"validation","validationCode":"boolean isValidIdentifier(String s) {\n    return java.util.regex.Pattern.compile(\"[\\\\p{Alnum}_]+\").matcher(s).matches();\n}\n// assert isValidIdentifier(tableName) before configuring the store","typeGuard":null,"tryCatchPattern":"try {\n    new MariaDBVectorStore(...);\n} catch (IllegalArgumentException e) {\n    if (e.getMessage().contains(\"should only contain alphanumeric\")) {\n        // fail fast with a rename hint\n    }\n}","preventionTips":["Adopt a naming convention of [a-zA-Z0-9_] for all DB identifiers.","Add config validation that rejects hyphens/dots/spaces in table/schema names at startup.","Never derive table names from untrusted user input.","Document allowed identifier format wherever vector store config is set."],"tags":["mariadb","sql-injection","identifier","validation"],"backgroundTag":"invalid-identifier-format","analyzedSha":"98a7beda4f29d80a71c5837eb4053b03a93a46f7","analyzedAt":"2026-09-11T14:15:49.441Z","contentChangedAt":"2026-09-11T14:15:49.441Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}