{"record":{"id":"fcdc44c60e4cc84f","repo":"Mintplex-Labs/anything-llm","slug":"invalid-folder-name","errorCode":null,"errorMessage":"Invalid folder name.","messagePattern":"Invalid folder name\\.","errorType":"http","errorClass":null,"httpStatus":500,"severity":"error","filePath":"server/endpoints/document.js","lineNumber":22,"sourceCode":"const {\n  flexUserRoleValid,\n  ROLES,\n} = require(\"../utils/middleware/multiUserProtected\");\nconst { validatedRequest } = require(\"../utils/middleware/validatedRequest\");\nconst fs = require(\"fs\");\nconst path = require(\"path\");\n\nfunction documentEndpoints(app) {\n  if (!app) return;\n  app.post(\n    \"/document/create-folder\",\n    [validatedRequest, flexUserRoleValid([ROLES.admin, ROLES.manager])],\n    async (request, response) => {\n      try {\n        const { name } = reqBody(request);\n        const storagePath = path.join(documentsPath, normalizePath(name));\n        if (!isWithin(path.resolve(documentsPath), path.resolve(storagePath)))\n          throw new Error(\"Invalid folder name.\");\n\n        if (fs.existsSync(storagePath)) {\n          response.status(500).json({\n            success: false,\n            message: \"Folder by that name already exists\",\n          });\n          return;\n        }\n\n        fs.mkdirSync(storagePath, { recursive: true });\n        response.status(200).json({ success: true, message: null });\n      } catch (e) {\n        console.error(e);\n        response.status(500).json({\n          success: false,\n          message: `Failed to create folder: ${e.message} `,\n        });\n      }","sourceCodeStart":4,"sourceCodeEnd":40,"githubUrl":"https://github.com/Mintplex-Labs/anything-llm/blob/3aec848f2885144aa8f1e53b9731a04310d5d558/server/endpoints/document.js#L4-L40","documentation":"The flex-UI twin of the API endpoint: POST /document/create-folder (admin/manager role) applies the same normalizePath + isWithin containment check on the folder name and throws 'Invalid folder name.' when the resolved path would leave documentsPath. Caught and returned as HTTP 500 'Failed to create folder: Invalid folder name. '. Same input rules as the API variant: relative names only, no parent traversal, no absolute components.","triggerScenarios":"Submitting the workspace 'create folder' form with a name containing '../' beyond the strip-able prefix, an absolute path, a Windows drive segment, or a name that normalizes to the documents root itself.","commonSituations":"Users pasting full paths ('/Client 2024/Invoices') into the folder-name field; copy-pasted names with trailing dots/separators that normalize oddly; automation scripts driving the flex endpoints with unsanitized names.","solutions":["Enter a plain relative name in the folder dialog ('Client 2024 Invoices'), then create subfolders separately if nesting is needed","Replace slashes and '..' with separators like '-' when the name originates from a filesystem path","If you are integrating programmatically, mirror the server rule: reject names that are not strictly relative and parent-free before submitting"],"exampleFix":"// before\nconst name = '/Client 2024/Invoices';   // absolute -> rejected\n// after\nconst name = 'Client 2024 - Invoices'; // relative, separator-free\nawait api.post('/document/create-folder', { name });","handlingStrategy":"validation","validationCode":"function isRelativeSafeName(name) {\n  return typeof name === 'string' && name.length > 0 && !name.includes('..') && !name.startsWith('/') && !name.startsWith('\\\\') && !/^[A-Za-z]:/.test(name);\n}\nif (!isRelativeSafeName(form.value.name)) { showFieldError('Use a plain folder name without slashes or ..'); return; }","typeGuard":"function isSafeFolderName(name: unknown): name is string { return typeof name === 'string' && name.length > 0 && !name.includes('..') && !/[\\\\/]/.test(name); }","tryCatchPattern":"try { await createFolder(name); } catch (e) { if (/Invalid folder name/.test(e.message)) { /* fix the input, show user-facing validation, do not re-POST the same value */ } else throw e; }","preventionTips":["Validate in the form/UI before submit: no slashes, no '..', plain display names","Convert pasted filesystem paths into flat names (replace separators with '-') at input time","Watch for the paired 500 'Folder by that name already exists' — the next most common create-folder failure"],"tags":["anythingllm","documents","folder-creation","path-traversal","flex-ui","validation"],"backgroundTag":"path-traversal-blocked","analyzedSha":"3aec848f2885144aa8f1e53b9731a04310d5d558","analyzedAt":"2026-08-18T10:02:21.017Z","contentChangedAt":"2026-08-18T10:02:21.017Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}