{"record":{"id":"fe0675962b369148","repo":"Mintplex-Labs/anything-llm","slug":"could-not-validate-login","errorCode":null,"errorMessage":"Could not validate login.","messagePattern":"Could not validate login\\.","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"frontend/src/models/system.js","lineNumber":143,"sourceCode":"  },\n\n  checkAuth: async function (currentToken = null) {\n    const valid = await fetch(`${API_BASE}/system/check-token`, {\n      headers: baseHeaders(currentToken),\n    })\n      .then((res) => res.ok)\n      .catch(() => false);\n\n    window.localStorage.setItem(AUTH_TIMESTAMP, Number(new Date()));\n    return valid;\n  },\n  requestToken: async function (body) {\n    return await fetch(`${API_BASE}/request-token`, {\n      method: \"POST\",\n      body: JSON.stringify({ ...body }),\n    })\n      .then((res) => {\n        if (!res.ok) throw new Error(\"Could not validate login.\");\n        return res.json();\n      })\n      .then((res) => res)\n      .catch((e) => {\n        return { valid: false, message: e.message };\n      });\n  },\n  /**\n   * Refreshes the user object from the session.\n   * @returns {Promise<{success: boolean, user: Object | null, message: string | null}>}\n   */\n  refreshUser: () => {\n    return fetch(`${API_BASE}/system/refresh-user`, {\n      headers: baseHeaders(),\n    })\n      .then((res) => {\n        if (!res.ok) throw new Error(\"Could not refresh user.\");\n        return res.json();","sourceCodeStart":125,"sourceCodeEnd":161,"githubUrl":"https://github.com/Mintplex-Labs/anything-llm/blob/20f6d3546c1938bfea1ad304f58a592dddcc5948/frontend/src/models/system.js#L125-L161","documentation":"Generic message thrown by requestToken in the AnythingLLM frontend when POST /api/request-token (username/password, optionally a 2FA code) responds non-2xx. The HTTP status and server message are discarded, so wrong credentials, a missing 2FA code, an unknown user, and a suspended account all surface as the same string.","triggerScenarios":"POSTing wrong username or password (401); valid credentials but the account has 2FA enabled and the `code` field is missing or wrong; the endpoint not mounted because multi-user mode is disabled (404); account suspended by an admin (403).","commonSituations":"Password changed elsewhere while a stale login form was open; 2FA enabled recently and the client still sends no code; server upgraded and the session/token format changed; single-user instance where login does not exist at all.","solutions":["Re-enter credentials carefully; if 2FA is enabled on the account, make sure the code field carries a current TOTP value.","Confirm multi-user mode is enabled on the server — single-user instances do not expose /request-token.","Inspect the Network tab for the real status: 401 bad credentials, 404 endpoint not mounted, 403 suspended account.","Reset the password (user flow or admin reset) if the password is genuinely lost."],"exampleFix":"// before\nif (!res.ok) throw new Error('Could not validate login.');\n\n// after — keep the server's message and status\nif (!res.ok) {\n  const data = await res.json().catch(() => null);\n  throw new Error(data?.message || `Could not validate login. (${res.status})`);\n}","handlingStrategy":"validation","validationCode":"// run before System.requestToken\nfunction validLoginBody(body) {\n  return (\n    typeof body?.username === 'string' && body.username.length > 0 &&\n    typeof body?.password === 'string' && body.password.length > 0\n  );\n}\nif (!validLoginBody(body)) throw new Error('Username and password are required');","typeGuard":null,"tryCatchPattern":"const { valid, message } = await System.requestToken(body);\nif (!valid) {\n  // message is 'Could not validate login.' — enrich with 2FA hint if code was absent\n  showLoginError(body.code ? message : `${message} If 2FA is enabled, enter your code.`);\n  return;\n}","preventionTips":["Clear old tokens/user objects from localStorage before re-login attempts.","Include the 2FA code field in the form whenever the account has 2FA enabled.","Confirm multi-user mode is enabled server-side before building login flows."],"tags":["anythingllm","authentication","login","http"],"backgroundTag":"login-failed","analyzedSha":"20f6d3546c1938bfea1ad304f58a592dddcc5948","analyzedAt":"2026-08-18T10:02:21.017Z","contentChangedAt":"2026-08-18T10:02:21.017Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}