{"record":{"id":"e55718f8715390b8","repo":"Mintplex-Labs/anything-llm","slug":"username-cannot-be-longer-than-64-characters","errorCode":null,"errorMessage":"Username cannot be longer than 64 characters","messagePattern":"Username cannot be longer than 64 characters","errorType":"validation","errorClass":null,"httpStatus":400,"severity":"warning","filePath":"server/models/user.js","lineNumber":39,"sourceCode":"    \"password\",\n    \"pfpFilename\",\n    \"role\",\n    \"suspended\",\n    \"dailyMessageLimit\",\n    \"bio\",\n  ],\n  validations: {\n    /**\n     * Unix-style username regex:\n     * - Must start with a lowercase letter\n     * - Can contain lowercase letters, digits, underscores, hyphens, @ signs, and periods\n     * - 2-64 characters long\n     */\n    username: (newValue = \"\") => {\n      try {\n        const username = String(newValue);\n        if (username.length > 64)\n          throw new Error(\"Username cannot be longer than 64 characters\");\n        if (username.length < 2)\n          throw new Error(\"Username must be at least 2 characters\");\n        if (!User.usernameRegex.test(username))\n          throw new Error(\n            \"Username must start with a lowercase letter and only contain lowercase letters, numbers, underscores, hyphens, and periods\"\n          );\n        return username;\n      } catch (e) {\n        throw new Error(e.message);\n      }\n    },\n    role: (role = \"default\") => {\n      const VALID_ROLES = [\"default\", \"admin\", \"manager\"];\n      if (!VALID_ROLES.includes(role)) {\n        throw new Error(\n          `Invalid role. Allowed roles are: ${VALID_ROLES.join(\", \")}`\n        );\n      }","sourceCodeStart":21,"sourceCodeEnd":57,"githubUrl":"https://github.com/Mintplex-Labs/anything-llm/blob/3aec848f2885144aa8f1e53b9731a04310d5d558/server/models/user.js#L21-L57","documentation":"The User model's username validator caps length at 64 characters (the overall regex window is 2-64). Values longer than 64 are rejected before any database write, so this is pure input validation, not a Prisma constraint error.","triggerScenarios":"Programmatic user creation mapping a full email or display name into username; SSO/OAuth payloads with long local parts; concatenated generated names (first.last+suffix@domain) exceeding 64 chars.","commonSituations":"Directory-sync and SSO provisioning flows; admin bulk-import scripts; seeders using realistic-but-long names.","solutions":["Derive a shorter username (e.g. use the email local part, truncated) instead of the full address","Enforce maxlength=64 plus client-side validation on signup/admin forms","For SSO mappings, add a truncation plus uniqueness suffix step"],"exampleFix":"// before\nUser.create({ username: 'very.long.email.address.2026+tags@extremely-long-domain.example.com', ... });\n\n// after\nconst username = email.split('@')[0].replace(/[^a-z0-9._-]/g, '').slice(0, 64) || `user_${Date.now()}`;\nUser.create({ username, ... });","handlingStrategy":"validation","validationCode":"const MAX_USERNAME = 64;\n\nif (typeof username !== 'string' || username.length > MAX_USERNAME) {\n  return res.status(400).json({ error: `username must be a string of at most ${MAX_USERNAME} characters` });\n}","typeGuard":null,"tryCatchPattern":"try {\n  await User.create({ username, password });\n} catch (err) {\n  if (/cannot be longer than 64 characters/.test(err.message)) {\n    return res.status(400).json({ error: 'Username too long (max 64)' });\n  }\n  throw err;\n}","preventionTips":["Set maxlength=64 on username inputs and validate before submit","When provisioning from SSO/email, derive a short unique username rather than reusing the full address","Run the same 2-64 + charset rules as the model in your form validation to fail early"],"tags":["user","validation","length-limit"],"backgroundTag":"field-length-limit-exceeded","analyzedSha":"3aec848f2885144aa8f1e53b9731a04310d5d558","analyzedAt":"2026-08-18T10:02:21.017Z","contentChangedAt":"2026-08-18T10:02:21.017Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}