affaan-m/ECC · error · HTTPException
Incorrect username or password
Error message
Incorrect username or password
What it means
Illustrative login handler from the fastapi-patterns skill: UserService.authenticate returned None for the submitted username/password pair. The deliberately vague message prevents username enumeration — either the user does not exist or the password is wrong.
Solutions
- Always return 401 with the same message for unknown user and wrong password
- Use constant-time password verification
- Add rate limiting on the token endpoint to slow credential stuffing
Defensive patterns
Strategy: validation
When it happens
Trigger: Thrown at skills/fastapi-patterns/SKILL.md:295 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of affaan-m/ECC@d8409a4b08 (2026-08-26).
Data as JSON: /api/errors/bb875db63562b689.
Report an issue: GitHub.
Appendix: source
Thrown at skills/fastapi-patterns/SKILL.md:295
service = UserService(db)
try:
user = await service.update(user_id, payload)
except DuplicateUserError:
raise HTTPException(status_code=400, detail="Email already registered")
if user is None:
raise HTTPException(status_code=404, detail="User not found")
return user
@router.post("/token")
async def login(
form_data: Annotated[OAuth2PasswordRequestForm, Depends()],
db: DbDep,
) -> dict[str, str]:
service = UserService(db)
token = await service.authenticate(form_data.username, form_data.password)
if token is None:
raise HTTPException(
status_code=status.HTTP_401_UNAUTHORIZED,
detail="Incorrect username or password",
headers={"WWW-Authenticate": "Bearer"},
)
return {"access_token": token, "token_type": "bearer"}
```
---
## Service Layer
```python
# app/services/user_service.py
from datetime import datetime, timedelta, timezone
from jose import jwt
from passlib.context import CryptContext
from sqlalchemy import func, selectView on GitHub (pinned to d8409a4b08)