toeverything/AFFiNE · warning · InvalidPasswordLength
invalid_password_length
invalid_password_length
Error message
Password must be between ${min} and ${max} characters What it means
assertValidPassword enforces the configured length bounds ({ min, max } from the auth password policy config) via zod; a password outside [min, max] throws invalid_password_length, reporting the exact configured bounds in the message.
Solutions
- Choose a password within the bounds shown in the error message
- Mirror the server's min/max in client validation and password hints
- For provisioning flows, generate passwords that satisfy the configured policy
Example fix
// before
await signUp(email, '123'); // shorter than min -> invalid_password_length
// after
if (password.length < MIN || password.length > MAX) {
throw new Error(`password must be ${MIN}-${MAX} characters`);
}
await signUp(email, password); Defensive patterns
Strategy: validation
Validate before calling
// mirror the server policy bounds before submit
const { min, max } = passwordPolicy; // from config/API
if (password.length < min || password.length > max) {
throw new Error(`password must be ${min}-${max} characters`);
} Type guard
function isValidPasswordLength(password: string, min: number, max: number): boolean {
return password.length >= min && password.length <= max;
} Try / catch
try {
await signUp(email, password);
} catch (e) {
if (e?.extensions?.code === 'INVALID_PASSWORD_LENGTH') showPasswordHint(e.extensions.min, e.extensions.max);
else throw e;
} Prevention
- Read the bounds from the error itself and mirror them in the UI hint
- Align client validation with the server's configured auth policy
- Provisioning scripts should generate passwords of compliant length
When it happens
Trigger: Sign-up or password change with a password shorter than the configured min (commonly 8) or longer than max; provisioning scripts generating short passwords; concatenation bugs producing overlong input.
Common situations: Server password policy tightened after clients shipped; SSO/LDAP provisioning with legacy short passwords; test fixtures using '123'.
Related errors
AI-assisted analysis of toeverything/AFFiNE@b4c8548c09 (2026-08-18).
Data as JSON: /api/errors/d185419dd2e254f6.
Report an issue: GitHub.
Appendix: source
Thrown at packages/backend/server/src/core/utils/validators.ts:19
import z from 'zod';
import { InvalidEmail, InvalidPasswordLength } from '../../base';
export function assertValidEmail(email: string) {
const result = z.string().email().safeParse(email);
if (!result.success) {
throw new InvalidEmail({ email });
}
}
export function assertValidPassword(
password: string,
{ min, max }: { min: number; max: number }
) {
const result = z.string().min(min).max(max).safeParse(password);
if (!result.success) {
throw new InvalidPasswordLength({ min, max });
}
}
export const validators = {
assertValidEmail,
assertValidPassword,
};
View on GitHub (pinned to b4c8548c09)