fix: validate account creation password
This commit is contained in:
1 parent
3ed3af1feb
commit
203bfb3246
5 files changed
+249
-10
No files matched your search
@@ -0,0 +1,61 @@
|
||||
# Task: Fix account registration invalid request parameters
|
||||
|
||||
## Identity
|
||||
|
||||
- Task ID: 20260902-registration-invalid-params-59f94692
|
||||
- Mode: Feature
|
||||
- Branch: codex/20260902-registration-invalid-params-59f94692-registration-invalid-params-59f94692
|
||||
- Worktree: /Users/inmanx/Documents/lwltAPI-registration-invalid-params-59f94692
|
||||
- Base commit: 3ed3af1feb503358b98fb57d3e8d97ab59d98129
|
||||
- Owner: codex
|
||||
- Status: Ready for Integration
|
||||
|
||||
## Scope
|
||||
|
||||
- Diagnose the current account-creation failure reported as “请求参数不符合要求”。
|
||||
- Correlate the operator form contract, API payload, server-side validation, privacy-safe runtime diagnostics, and account authorization tests.
|
||||
- Add a narrowly scoped client-side validation and error-feedback fix plus regression coverage.
|
||||
- Do not create or change a real account, read secrets or request payloads, deploy, restart the service, or modify ERP behavior.
|
||||
|
||||
## Intent And Constraints
|
||||
|
||||
- Preserve the accepted fixed-scope `admin` / `team_lead` / `user` account and authorization model.
|
||||
- Keep the server-side 12–512-character password boundary unchanged; prevent invalid form input from reaching the API and retain a safe backend-validation fallback.
|
||||
- Use runtime diagnostics only for validation field names; do not persist account names, passwords, request bodies, or other user data.
|
||||
- Treat the concurrent compact-dashboard task as a file-level overlap warning only; keep this change limited to the account form and its tests for later reconciliation.
|
||||
|
||||
## Outcome
|
||||
|
||||
- Privacy-safe diagnostics from the running standard service showed the two recent HTTP validation failures both had only `validation_paths=["password"]`; no request content was inspected.
|
||||
- Confirmed the mismatch: the API requires a 12–512-character password, while the account form used `novalidate` and submitted without an equivalent client-side check, causing a short password to surface only as the generic Zod response.
|
||||
- Added deterministic account-create validation before any API request. Invalid username, password, or role values now show a Chinese field-specific message, mark and focus the relevant field, and do not send a request.
|
||||
- Preserved safe backend fallback handling by retaining `error_code` and validation paths from API errors and mapping a server-side password rejection to the same actionable message.
|
||||
- Added the password requirement beside the form field and added focused regression coverage for short-password rejection, valid request normalization, backend fallback messaging, and visible form guidance.
|
||||
- No live account, database, service process, deployment, ERP state, or external system was changed.
|
||||
|
||||
## Verification
|
||||
|
||||
- Focused account-form regression: 4/4 passed.
|
||||
- Focused account-authorization regression: 8/8 passed.
|
||||
- `node --check LianSyn-platform/app.js`: passed.
|
||||
- `git diff --check`: passed before the final documentation update.
|
||||
- `node --run check:repo`: 10/10 passed.
|
||||
- `node --run check`: passed.
|
||||
- `node --run test:control-plane`: 153/153 passed.
|
||||
- `node --run test:legacy`: 260/260 passed, including the new four tests.
|
||||
- `node --run build`: passed.
|
||||
- `check_project_docs.py`: passed.
|
||||
- `check_doc_drift.py --task-id 20260902-registration-invalid-params-59f94692`: passed.
|
||||
- Verification used the bundled Node runtime and a temporary ignored `node_modules` symlink to the existing dependency tree because Node was not on the isolated shell `PATH`.
|
||||
|
||||
## Follow-ups
|
||||
|
||||
- Integrate this isolated feature change with the concurrent dashboard layout work, then restart or redeploy the standard service only under separate explicit authorization before expecting the live `/accounts` page to change.
|
||||
|
||||
## Promotion Candidates
|
||||
|
||||
- None recorded.
|
||||
|
||||
## Supporting Records
|
||||
|
||||
- [Account registration password validation evidence](../../50-evidence/topics/20260902-registration-invalid-params-59f94692__account-registration-password-validation.md)
|
||||
Reference in new issue
Block a user