pub fn valid_username(username: &str) -> boolExpand description
Whether a normalized username is one the web admin can address.
The panel routes every colleague operation at /ui/operators/{username}/…
and builds those paths by interpolation, so a name holding /, ?, # or
a space produces a URL that matches no route — the operator is creatable
from the host and then unmanageable from the panel. minijinja escapes HTML,
not URL syntax, so the templates cannot rescue it either.
The same rule this tree already applies wherever a configured name becomes a
path or an environment segment (valid_profile_name,
valid_config_key_name), widened by _ and . because an operator name is
a person’s, not a slug — a.smith and a_smith are ordinary and neither
means anything to a URL.
Checked at creation only. An existing row is left alone: refusing to load a username would lock somebody out of a panel they are already using, which is the opposite of what this is for.