{"record":{"id":"d185419dd2e254f6","repo":"toeverything/AFFiNE","slug":"invalid-password-length","errorCode":"invalid_password_length","errorMessage":"Password must be between ${min} and ${max} characters","messagePattern":"Password must be between (.+?) and (.+?) characters","errorType":"exception","errorClass":"InvalidPasswordLength","httpStatus":400,"severity":"warning","filePath":"packages/backend/server/src/core/utils/validators.ts","lineNumber":19,"sourceCode":"import z from 'zod';\n\nimport { InvalidEmail, InvalidPasswordLength } from '../../base';\n\nexport function assertValidEmail(email: string) {\n  const result = z.string().email().safeParse(email);\n  if (!result.success) {\n    throw new InvalidEmail({ email });\n  }\n}\n\nexport function assertValidPassword(\n  password: string,\n  { min, max }: { min: number; max: number }\n) {\n  const result = z.string().min(min).max(max).safeParse(password);\n\n  if (!result.success) {\n    throw new InvalidPasswordLength({ min, max });\n  }\n}\n\nexport const validators = {\n  assertValidEmail,\n  assertValidPassword,\n};\n","sourceCodeStart":1,"sourceCodeEnd":27,"githubUrl":"https://github.com/toeverything/AFFiNE/blob/b4c8548c09da21b2898443559a5b846f0ccf5dd8/packages/backend/server/src/core/utils/validators.ts#L1-L27","documentation":"assertValidPassword enforces the configured length bounds ({ min, max } from the auth password policy config) via zod; a password outside [min, max] throws invalid_password_length, reporting the exact configured bounds in the message.","triggerScenarios":"Sign-up or password change with a password shorter than the configured min (commonly 8) or longer than max; provisioning scripts generating short passwords; concatenation bugs producing overlong input.","commonSituations":"Server password policy tightened after clients shipped; SSO/LDAP provisioning with legacy short passwords; test fixtures using '123'.","solutions":["Choose a password within the bounds shown in the error message","Mirror the server's min/max in client validation and password hints","For provisioning flows, generate passwords that satisfy the configured policy"],"exampleFix":"// before\nawait signUp(email, '123'); // shorter than min -> invalid_password_length\n\n// after\nif (password.length < MIN || password.length > MAX) {\n  throw new Error(`password must be ${MIN}-${MAX} characters`);\n}\nawait signUp(email, password);","handlingStrategy":"validation","validationCode":"// mirror the server policy bounds before submit\nconst { min, max } = passwordPolicy; // from config/API\nif (password.length < min || password.length > max) {\n  throw new Error(`password must be ${min}-${max} characters`);\n}","typeGuard":"function isValidPasswordLength(password: string, min: number, max: number): boolean {\n  return password.length >= min && password.length <= max;\n}","tryCatchPattern":"try {\n  await signUp(email, password);\n} catch (e) {\n  if (e?.extensions?.code === 'INVALID_PASSWORD_LENGTH') showPasswordHint(e.extensions.min, e.extensions.max);\n  else throw e;\n}","preventionTips":["Read the bounds from the error itself and mirror them in the UI hint","Align client validation with the server's configured auth policy","Provisioning scripts should generate passwords of compliant length"],"tags":["validation","password","auth","input"],"backgroundTag":"password-validation-failed","analyzedSha":"b4c8548c09da21b2898443559a5b846f0ccf5dd8","analyzedAt":"2026-08-18T21:16:52.546Z","contentChangedAt":"2026-08-18T21:16:52.546Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}