affaan-m/ECC · error · HTTPException

Incorrect username or password

Error message

Incorrect username or password

What it means

Illustrative login handler from the fastapi-patterns skill: UserService.authenticate returned None for the submitted username/password pair. The deliberately vague message prevents username enumeration — either the user does not exist or the password is wrong.

Solutions

  1. Always return 401 with the same message for unknown user and wrong password
  2. Use constant-time password verification
  3. Add rate limiting on the token endpoint to slow credential stuffing
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at skills/fastapi-patterns/SKILL.md:295 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of affaan-m/ECC@d8409a4b08 (2026-08-26). Data as JSON: /api/errors/bb875db63562b689. Report an issue: GitHub.

Appendix: source

Thrown at skills/fastapi-patterns/SKILL.md:295

    service = UserService(db)
    try:
        user = await service.update(user_id, payload)
    except DuplicateUserError:
        raise HTTPException(status_code=400, detail="Email already registered")
    if user is None:
        raise HTTPException(status_code=404, detail="User not found")
    return user


@router.post("/token")
async def login(
    form_data: Annotated[OAuth2PasswordRequestForm, Depends()],
    db: DbDep,
) -> dict[str, str]:
    service = UserService(db)
    token = await service.authenticate(form_data.username, form_data.password)
    if token is None:
        raise HTTPException(
            status_code=status.HTTP_401_UNAUTHORIZED,
            detail="Incorrect username or password",
            headers={"WWW-Authenticate": "Bearer"},
        )
    return {"access_token": token, "token_type": "bearer"}
```

---

## Service Layer

```python
# app/services/user_service.py
from datetime import datetime, timedelta, timezone

from jose import jwt
from passlib.context import CryptContext
from sqlalchemy import func, select

View on GitHub (pinned to d8409a4b08)