ruvnet/ruflo · error · Error

Invalid schema name: " ". Must contain only letters…

Error message

Invalid schema name: "${schema}". Must contain only letters, digits, and underscores, and start with a letter or underscore.

What it means

validateSchemaName() only accepts identifiers matching ^[a-zA-Z_][a-zA-Z0-9_]*$ — ASCII letters, digits, and underscores, starting with a letter or underscore — because names matching that pattern can be interpolated into SQL unquoted. Hyphens, spaces, unicode, or a leading digit throw this error.

Solutions

  1. Replace hyphens with underscores: my-schema -> my_schema
  2. Prefix digit-leading names with an underscore or letter
  3. Keep the schema to ASCII [A-Za-z0-9_] and have it start with a letter or underscore

Example fix

# before
ruflo ruvector ... --schema my-vector-schema

# after
ruflo ruvector ... --schema my_vector_schema
Defensive patterns

Strategy: validation

Validate before calling

function toPgIdentifier(raw: string): string {
  const cleaned = raw.replace(/[^a-zA-Z0-9_]/g, '_');
  return /^[a-zA-Z_]/.test(cleaned) ? cleaned : `_${cleaned}`;
}
const schema = toPgIdentifier(userInput); // safe before it reaches the CLI

Type guard

function isPgIdentifier(v: unknown): v is string {
  return typeof v === 'string' && /^[a-zA-Z_][a-zA-Z0-9_]*$/.test(v) && v.length <= 63;
}

Prevention

When it happens

Trigger: Passing kebab-case names (my-schema), names starting with a digit (2fa_data), or anything containing -, ., :, /, or non-ASCII characters as the schema.

Common situations: Translating npm-style kebab-case package or namespace names into schema names; templating schema names from URLs or file paths that contain dashes.

Related errors


AI-assisted analysis of ruvnet/ruflo@fa13ee4ad6 (2026-08-18). Data as JSON: /api/errors/dec5f9bd84e85a30. Report an issue: GitHub.

Appendix: source

Thrown at v3/@claude-flow/cli/src/commands/ruvector/pg-utils.ts:28

 * Allows only ASCII letters, digits, and underscores.
 * Must start with a letter or underscore.
 */
const VALID_PG_IDENTIFIER = /^[a-zA-Z_][a-zA-Z0-9_]*$/;

/**
 * Validate a PostgreSQL schema name.
 * Throws if the name contains characters that could enable SQL injection.
 * Safe names are returned as-is (no quoting needed since they match the identifier pattern).
 */
export function validateSchemaName(schema: string): string {
  if (!schema || schema.length === 0) {
    throw new Error('Schema name must not be empty');
  }
  if (schema.length > 63) {
    throw new Error(`Schema name too long (${schema.length} chars, max 63): "${schema}"`);
  }
  if (!VALID_PG_IDENTIFIER.test(schema)) {
    throw new Error(
      `Invalid schema name: "${schema}". Must contain only letters, digits, and underscores, and start with a letter or underscore.`
    );
  }
  return schema;
}

/**
 * Validate a PostgreSQL timestamp string.
 * Only allows ISO 8601 format to prevent SQL injection via timestamp fields.
 */
const VALID_TIMESTAMP = /^\d{4}-\d{2}-\d{2}[T ]\d{2}:\d{2}:\d{2}(\.\d+)?(Z|[+-]\d{2}:?\d{2})?$/;

export function validateTimestamp(value: string): string {
  if (!VALID_TIMESTAMP.test(value)) {
    throw new Error(`Invalid timestamp format: "${value}". Expected ISO 8601.`);
  }
  return value;
}

View on GitHub (pinned to fa13ee4ad6)