toeverything/AFFiNE · error · WrongSignInMethod
wrong_sign_in_method
wrong_sign_in_method
Error message
You are trying to sign in by a different method than you signed up with.
What it means
WrongSignInMethod, thrown by UserModel.signIn (user.ts:150-152) when the email resolves to a user but that user's password column is null - the account was created through a different sign-in method (e.g. OAuth) and has no password to verify. The message tells the user they are trying a different method than the one they signed up with.
Solutions
- Sign in with the original provider (OAuth) instead of password
- Attach a password via the set/reset-password flow, then retry
- Branch before calling signIn when the account has no password and route to the provider flow
Example fix
// before
await user.signIn(email, password); // throws wrong_sign_in_method
// after
const existing = await user.getUserByEmail(email);
if (existing && !existing.password) {
// route to the OAuth sign-in flow for this account
} else {
await user.signIn(email, password);
} Defensive patterns
Strategy: fallback
Validate before calling
const existing = await user.getUserByEmail(email);
if (existing && !existing.password) {
// route to the OAuth provider this account was created with
} else {
await user.signIn(email, password);
} Type guard
const isPasswordlessUser = (
u: { password?: string | null } | null
): u is { password: null } => !!u && !u.password; Try / catch
try {
await user.signIn(email, password);
} catch (e) {
if (e instanceof WrongSignInMethod) {
// fall back to the provider sign-in flow for this account
}
throw e;
} Prevention
- Store the sign-in method on the account and branch before password auth
- Offer 'continue with provider' when the account has no password
- After OAuth signup, let users set a password if they also want password login
When it happens
Trigger: signIn(email, password) for a user whose password is null: OAuth-registered accounts, or instances where the password hash was never set or was lost in migration.
Common situations: User signs up with Google and later tries email+password; password migration dropped hashes; the same email used for both OAuth and local signup flows.
Related errors
- invalid_password_length
- wrong_sign_in_credentials
- wrong_sign_in_credentials
- action_forbidden
- action_forbidden
AI-assisted analysis of toeverything/AFFiNE@b4c8548c09 (2026-08-18).
Data as JSON: /api/errors/b490d3ea0b796cfc.
Report an issue: GitHub.
Appendix: source
Thrown at packages/backend/server/src/models/user.ts:150
const rows = await this.db.$queryRaw<User[]>`
SELECT id, name, email, password, registered, email_verified as "emailVerifiedAt", avatar_url as "avatarUrl", registered, created_at as "createdAt", disabled
FROM "users"
WHERE lower("email") = lower(${email})
${Prisma.raw(filter.withDisabled ? '' : 'AND disabled = false')}
`;
return rows[0] ?? null;
}
async signIn(email: string, password: string): Promise<User> {
const user = await this.getUserByEmail(email);
if (!user) {
throw new WrongSignInCredentials({ email });
}
if (!user.password) {
throw new WrongSignInMethod();
}
const passwordMatches = await this.crypto.verifyPassword(
password,
user.password
);
if (!passwordMatches) {
throw new WrongSignInCredentials({ email });
}
return user;
}
async getPublicUserByEmail(email: string): Promise<PublicUser | null> {
const rows = await this.db.$queryRaw<PublicUser[]>`
SELECT id, name, avatar_url as "avatarUrl"
FROM "users"View on GitHub (pinned to b4c8548c09)