# Prevent Google OAuth2 users getting username "user1", "user2"...?

**URL:** https://meta.discourse.org/t/prevent-google-oauth2-users-getting-username-user1-user2/379798
**Category:** Support
**Created:** [August 22, 2025, 7:59am UTC](https://meta.discourse.org/t/prevent-google-oauth2-users-getting-username-user1-user2/379798 "2025-08-22T07:59:01Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![ToddZ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/toddz/32/328350_2.png) [@ToddZ](https://meta.discourse.org/u/ToddZ)
#### Post date: [August 22, 2025, 7:59am UTC](https://meta.discourse.org/t/prevent-google-oauth2-users-getting-username-user1-user2/379798/1 "2025-08-22T07:59:01Z")

</div>

I prefer (thus far anyway) to run my forum showing usernames vs. real names, and I’ve made the real name field optional.

But some of my Google OAuth2 (“Sign in with Google”) users have gotten what are apparently default usernames of “ **User1** ”, “ **User2** ”, etc.

I really don’t like having these generic defaults in the mix.

It looks like this occurs here on meta as well:

 ![image](https://global.discourse-cdn.com/meta/original/4X/2/b/8/2b8372d25e98c97b11a576d794ad643c35322bc5.png)

I don’t know why this happens for a few Google OAuth2 users but not for most. I’d welcome any insight.

I suppose I could rethink my emphasis on usernames. But is there any way to prevent this “**User[X]**” behavior, short of disabling Oauth2 signups?

---

<div class="post-metadata">

### Author: ![chapoi](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/chapoi/32/537252_2.png) [@chapoi](https://meta.discourse.org/u/chapoi)
#### Post date: [August 22, 2025, 8:36am UTC](https://meta.discourse.org/t/prevent-google-oauth2-users-getting-username-user1-user2/379798/2 "2025-08-22T08:36:26Z")

</div>

> [@ToddZ](#):
>
> I don’t know why this happens for a few Google OAuth2 users but not for most. I’d welcome any insight.

Bit of guesswork on my part, but could it be that their usernames contained spaces or special characters? That’s not allowed in Discourse usernames.

But @pmusaraj will know a lot better, I’m curious too now 🙂

---

<div class="post-metadata">

### Author: ![pmusaraj](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pmusaraj/32/119489_2.png) [@pmusaraj](https://meta.discourse.org/u/pmusaraj)
#### Post date: [August 22, 2025, 4:00pm UTC](https://meta.discourse.org/t/prevent-google-oauth2-users-getting-username-user1-user2/379798/3 "2025-08-22T16:00:35Z")

</div>

I am pretty sure this is coming from this site setting

 ![image](https://global.discourse-cdn.com/meta/original/4X/8/a/9/8a9e9b8650939172775a7689337ed3b16aa8aa3d.png)

If unchecked, the username picker will default to `userN`, especially if the user doesn’t have a display name in their upstream account.

Security 1, convenience 0 😀

---

<div class="post-metadata">

### Author: ![ToddZ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/toddz/32/328350_2.png) [@ToddZ](https://meta.discourse.org/u/ToddZ)
#### Post date: [August 22, 2025, 4:14pm UTC](https://meta.discourse.org/t/prevent-google-oauth2-users-getting-username-user1-user2/379798/5 "2025-08-22T16:14:56Z")

</div>

> [@pmusaraj](#):
>
> If unchecked, the username picker will default to `userN`, especially if the user doesn’t have a display name in their upstream account.

Thank you! This exact explanation would be a useful addition to the option text.

I may end up checking that box. Since people can edit the suggested names, the risk seems low.

---

<div class="post-metadata">

### Author: ![lindsey](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/lindsey/32/318210_2.png) [@lindsey](https://meta.discourse.org/u/lindsey)
#### Post date: [August 22, 2025, 5:55pm UTC](https://meta.discourse.org/t/prevent-google-oauth2-users-getting-username-user1-user2/379798/8 "2025-08-22T17:55:55Z")

</div>

When `use email for username and name suggestions` is disabled, we could leave the username field blank at signup instead of suggesting `userN` — we’ve done something similar in our admin account signups on new Discourse sites.

Is that something you think you’d like to see for your site members, too, @ToddZ?

---

<div class="post-metadata">

### Author: ![ToddZ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/toddz/32/328350_2.png) [@ToddZ](https://meta.discourse.org/u/ToddZ)
#### Post date: [August 23, 2025, 6:41pm UTC](https://meta.discourse.org/t/prevent-google-oauth2-users-getting-username-user1-user2/379798/9 "2025-08-23T18:41:36Z")

</div>

I would much prefer that, myself. I’d rather see people mash the keyboard and come up with a nonsense username (or hook into a [username generator API](https://randomusernameapi.github.io/)) than end up with a bunch of `userN`.

I can’t quite imagine a reason to prefer `userN`, but if I’m missing something, maybe an optional setting could make everyone happy.

---

<div class="post-metadata">

### Author: ![system](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/system/32/443519_2.png) [@system](https://meta.discourse.org/u/system)
#### Post date: [September 22, 2025, 6:42pm UTC](https://meta.discourse.org/t/prevent-google-oauth2-users-getting-username-user1-user2/379798/10 "2025-09-22T18:42:08Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
