Space not allowed for username despite Import mode disabled

We have a custom database for our Auth0 application.

We tried to send a password change ticket to Auth0. It responded with:

"DB Custom script (get_user): invalid fields. Username can only contain alphanumeric characters and the following characters: '_', '+', '-', '.', '!', '#', '$', ''', '^', '', '~' and '@'."

Per this Knowledge Base article:

When using custom databases the behaviour is slightly different depending on whether import mode enabled.

If disabled:

The rules for allowed characters does not apply i.e. you can use any characters for username and it will be accepted.

When I look at our DB config:

  • “Import Users to Auth0” Is turned OFF. I presume this means import mode is disabled.

  • Under Attributes → Username Configuration: “Use Username as Identifier” is ON.

Should we expect that error to NOT happen, since import mode is off?

Hi @alex57

Welcome back to the Auth0 Community!

Could you let me know what special characters does the user contain which would trigger the error?

Kind Regards,
Nik

Hi @nik.baleca , thanks for the reply. It’s a space character.

Cheers,

Alex

Hi again.

You have a custom database configured in Auth0 with "Import Users to Auth0" turned OFF and "Use Username as Identifier" turned ON. When you attempt to send a password change ticket, Auth0 returns a validation error: "invalid fields. Username can only contain alphanumeric characters and the following characters: '_', '+', '-', '.', '!', '#', '$', ''', '^', '', '~' and '@'."

However, according to the official Auth0 documentation on allowed characters for usernames, Auth0 explicitly states: "No other characters/symbols are allowed, and Auth0 does not validate or sanitize custom database inputs."

[Root Cause]

Auth0 is performing character validation on your custom database when the Get User script returns the username.

[Solution]

You will need to normalize the username in order to exclude the white space from the username or remove the space from the external database in order for the password change ticket to work.

Kind Regards,
Nik