{"record":{"id":"bb875db63562b689","repo":"affaan-m/ECC","slug":"incorrect-username-or-password","errorCode":null,"errorMessage":"Incorrect username or password","messagePattern":"Incorrect username or password","errorType":"http","errorClass":"HTTPException","httpStatus":401,"severity":"error","filePath":"skills/fastapi-patterns/SKILL.md","lineNumber":295,"sourceCode":"    service = UserService(db)\n    try:\n        user = await service.update(user_id, payload)\n    except DuplicateUserError:\n        raise HTTPException(status_code=400, detail=\"Email already registered\")\n    if user is None:\n        raise HTTPException(status_code=404, detail=\"User not found\")\n    return user\n\n\n@router.post(\"/token\")\nasync def login(\n    form_data: Annotated[OAuth2PasswordRequestForm, Depends()],\n    db: DbDep,\n) -> dict[str, str]:\n    service = UserService(db)\n    token = await service.authenticate(form_data.username, form_data.password)\n    if token is None:\n        raise HTTPException(\n            status_code=status.HTTP_401_UNAUTHORIZED,\n            detail=\"Incorrect username or password\",\n            headers={\"WWW-Authenticate\": \"Bearer\"},\n        )\n    return {\"access_token\": token, \"token_type\": \"bearer\"}\n```\n\n---\n\n## Service Layer\n\n```python\n# app/services/user_service.py\nfrom datetime import datetime, timedelta, timezone\n\nfrom jose import jwt\nfrom passlib.context import CryptContext\nfrom sqlalchemy import func, select","sourceCodeStart":277,"sourceCodeEnd":313,"githubUrl":"https://github.com/affaan-m/ECC/blob/d8409a4b0813771235555e32e3d8046a73988bfa/skills/fastapi-patterns/SKILL.md#L277-L313","documentation":"Illustrative login handler from the fastapi-patterns skill: UserService.authenticate returned None for the submitted username/password pair. The deliberately vague message prevents username enumeration — either the user does not exist or the password is wrong.","triggerScenarios":"Thrown at skills/fastapi-patterns/SKILL.md:295 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Always return 401 with the same message for unknown user and wrong password","Use constant-time password verification","Add rate limiting on the token endpoint to slow credential stuffing"],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"d8409a4b0813771235555e32e3d8046a73988bfa","analyzedAt":"2026-08-26T12:15:34.022Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}