{"record":{"id":"8ec8b23f6df01073","repo":"toeverything/AFFiNE","slug":"invalid-email-8ec8b2","errorCode":"invalid_email","errorMessage":"An invalid email provided: ${email}","messagePattern":"An invalid email provided: (.+?)","errorType":"exception","errorClass":"InvalidEmail","httpStatus":400,"severity":"warning","filePath":"packages/backend/server/src/core/utils/validators.ts","lineNumber":8,"sourceCode":"import z from 'zod';\n\nimport { InvalidEmail, InvalidPasswordLength } from '../../base';\n\nexport function assertValidEmail(email: string) {\n  const result = z.string().email().safeParse(email);\n  if (!result.success) {\n    throw new InvalidEmail({ email });\n  }\n}\n\nexport function assertValidPassword(\n  password: string,\n  { min, max }: { min: number; max: number }\n) {\n  const result = z.string().min(min).max(max).safeParse(password);\n\n  if (!result.success) {\n    throw new InvalidPasswordLength({ min, max });\n  }\n}\n\nexport const validators = {\n  assertValidEmail,\n  assertValidPassword,\n};","sourceCodeStart":1,"sourceCodeEnd":26,"githubUrl":"https://github.com/toeverything/AFFiNE/blob/b4c8548c09da21b2898443559a5b846f0ccf5dd8/packages/backend/server/src/core/utils/validators.ts#L1-L26","documentation":"assertValidEmail runs the input through zod's z.string().email() and throws invalid_email (with the offending value) when the string is not a well-formed address. Auth flows call it before touching the database, so malformed emails never reach user lookup.","triggerScenarios":"Sign-up/sign-in/email-change with a malformed address (missing @, spaces, bare username); sending a username or display name in the email field; untrimmed whitespace-padded input.","commonSituations":"Forms without client-side validation; password managers filling the wrong field; API consumers sending { username } instead of { email }.","solutions":["Send a valid email address in the email field","Mirror the same validation client-side (zod or regex) before submit","Trim whitespace from form inputs before sending"],"exampleFix":"// before\nawait signIn(emailInput, password); // 'user name@host' -> invalid_email\n\n// after\nconst email = emailInput.trim();\nif (!/^[^@\\s]+@[^@\\s]+\\.[^@\\s]+$/.test(email)) throw new Error('enter a valid email');\nawait signIn(email, password);","handlingStrategy":"validation","validationCode":"// client-side pre-check matching the server rule\nconst email = raw.trim();\nif (!/^[^@\\s]+@[^@\\s]+\\.[^@\\s]+$/.test(email)) {\n  throw new Error('enter a valid email address');\n}","typeGuard":"function isValidEmail(email: string): boolean {\n  return z.string().email().safeParse(email.trim()).success;\n}","tryCatchPattern":"try {\n  await signUp(email, password);\n} catch (e) {\n  if (e?.extensions?.code === 'INVALID_EMAIL') markEmailFieldInvalid();\n  else throw e;\n}","preventionTips":["Validate email format client-side with the same zod rule the server uses","Trim inputs before submission","Confirm you are sending the email field, not a username or display name"],"tags":["validation","email","auth","input"],"backgroundTag":"email-validation-failed","analyzedSha":"b4c8548c09da21b2898443559a5b846f0ccf5dd8","analyzedAt":"2026-08-18T21:16:52.546Z","contentChangedAt":"2026-08-18T21:16:52.546Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}