Skip to content

feat(utilities): forbid usernames ending in .md - #706

Merged
marekh19 merged 1 commit into
masterfrom
feat/forbid-md-username-suffix
Sep 16, 2026
Merged

marekh19 merged 1 commit into
masterfrom
feat/forbid-md-username-suffix

Conversation

@marekh19

@marekh19 marekh19 commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

Part of apify/apify-web#6604

Replaces the AGENTS.md, CLAUDE.md and auth.md entries in the forbidden username list with a single (.*\.md) pattern, so no new username can end in .md. apify.com serves a markdown twin of many pages at <path>.md, so such a username collides with that route.

We have only a 1 production username ending in .md with a public profile. I will create an exception on the web for that user.

Deliberately not added to USERNAME.REGEX. That regex runs on every user-record write through core's UserIdentitySchema, so it would invalidate the 20+ existing accounts whose username already ends in .md. By contrast isForbiddenUsername() runs only when a username is picked or changed, in validateUsername(), which org creation also goes through. Existing holders keep their username and need no migration.

@marekh19 marekh19 added the t-web Issues with this label are in the ownership of the web team. label Sep 16, 2026
@marekh19 marekh19 self-assigned this Sep 16, 2026
@marekh19
marekh19 marked this pull request as ready for review September 16, 2026 11:49
@apify-service-account apify-service-account added the tested Temporary label used only programatically for some analytics. label Sep 16, 2026
@marekh19
marekh19 merged commit 36978f3 into master Sep 16, 2026
14 of 17 checks passed
@marekh19
marekh19 deleted the feat/forbid-md-username-suffix branch September 16, 2026 12:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

t-web Issues with this label are in the ownership of the web team. tested Temporary label used only programatically for some analytics.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants