toeverything/AFFiNE · warning · InvalidPasswordLength

invalid_password_length

invalid_password_length

Error message

Password must be between ${min} and ${max} characters

What it means

assertValidPassword enforces the configured length bounds ({ min, max } from the auth password policy config) via zod; a password outside [min, max] throws invalid_password_length, reporting the exact configured bounds in the message.

Solutions

  1. Choose a password within the bounds shown in the error message
  2. Mirror the server's min/max in client validation and password hints
  3. For provisioning flows, generate passwords that satisfy the configured policy

Example fix

// before
await signUp(email, '123'); // shorter than min -> invalid_password_length

// after
if (password.length < MIN || password.length > MAX) {
  throw new Error(`password must be ${MIN}-${MAX} characters`);
}
await signUp(email, password);
Defensive patterns

Strategy: validation

Validate before calling

// mirror the server policy bounds before submit
const { min, max } = passwordPolicy; // from config/API
if (password.length < min || password.length > max) {
  throw new Error(`password must be ${min}-${max} characters`);
}

Type guard

function isValidPasswordLength(password: string, min: number, max: number): boolean {
  return password.length >= min && password.length <= max;
}

Try / catch

try {
  await signUp(email, password);
} catch (e) {
  if (e?.extensions?.code === 'INVALID_PASSWORD_LENGTH') showPasswordHint(e.extensions.min, e.extensions.max);
  else throw e;
}

Prevention

When it happens

Trigger: Sign-up or password change with a password shorter than the configured min (commonly 8) or longer than max; provisioning scripts generating short passwords; concatenation bugs producing overlong input.

Common situations: Server password policy tightened after clients shipped; SSO/LDAP provisioning with legacy short passwords; test fixtures using '123'.

Related errors


AI-assisted analysis of toeverything/AFFiNE@b4c8548c09 (2026-08-18). Data as JSON: /api/errors/d185419dd2e254f6. Report an issue: GitHub.

Appendix: source

Thrown at packages/backend/server/src/core/utils/validators.ts:19

import z from 'zod';

import { InvalidEmail, InvalidPasswordLength } from '../../base';

export function assertValidEmail(email: string) {
  const result = z.string().email().safeParse(email);
  if (!result.success) {
    throw new InvalidEmail({ email });
  }
}

export function assertValidPassword(
  password: string,
  { min, max }: { min: number; max: number }
) {
  const result = z.string().min(min).max(max).safeParse(password);

  if (!result.success) {
    throw new InvalidPasswordLength({ min, max });
  }
}

export const validators = {
  assertValidEmail,
  assertValidPassword,
};

View on GitHub (pinned to b4c8548c09)