fix: validate account creation password

This commit is contained in:
inman committed 2026-09-02 11:00:13 +08:00
1 parent 3ed3af1feb
commit 203bfb3246
5 files changed
+249 -10

No files matched your search

@@ -0,0 +1,61 @@
# Task: Fix account registration invalid request parameters
## Identity
- Task ID: 20260902-registration-invalid-params-59f94692
- Mode: Feature
- Branch: codex/20260902-registration-invalid-params-59f94692-registration-invalid-params-59f94692
- Worktree: /Users/inmanx/Documents/lwltAPI-registration-invalid-params-59f94692
- Base commit: 3ed3af1feb503358b98fb57d3e8d97ab59d98129
- Owner: codex
- Status: Ready for Integration
## Scope
- Diagnose the current account-creation failure reported as “请求参数不符合要求”。
- Correlate the operator form contract, API payload, server-side validation, privacy-safe runtime diagnostics, and account authorization tests.
- Add a narrowly scoped client-side validation and error-feedback fix plus regression coverage.
- Do not create or change a real account, read secrets or request payloads, deploy, restart the service, or modify ERP behavior.
## Intent And Constraints
- Preserve the accepted fixed-scope `admin` / `team_lead` / `user` account and authorization model.
- Keep the server-side 12–512-character password boundary unchanged; prevent invalid form input from reaching the API and retain a safe backend-validation fallback.
- Use runtime diagnostics only for validation field names; do not persist account names, passwords, request bodies, or other user data.
- Treat the concurrent compact-dashboard task as a file-level overlap warning only; keep this change limited to the account form and its tests for later reconciliation.
## Outcome
- Privacy-safe diagnostics from the running standard service showed the two recent HTTP validation failures both had only `validation_paths=["password"]`; no request content was inspected.
- Confirmed the mismatch: the API requires a 12–512-character password, while the account form used `novalidate` and submitted without an equivalent client-side check, causing a short password to surface only as the generic Zod response.
- Added deterministic account-create validation before any API request. Invalid username, password, or role values now show a Chinese field-specific message, mark and focus the relevant field, and do not send a request.
- Preserved safe backend fallback handling by retaining `error_code` and validation paths from API errors and mapping a server-side password rejection to the same actionable message.
- Added the password requirement beside the form field and added focused regression coverage for short-password rejection, valid request normalization, backend fallback messaging, and visible form guidance.
- No live account, database, service process, deployment, ERP state, or external system was changed.
## Verification
- Focused account-form regression: 4/4 passed.
- Focused account-authorization regression: 8/8 passed.
- `node --check LianSyn-platform/app.js`: passed.
- `git diff --check`: passed before the final documentation update.
- `node --run check:repo`: 10/10 passed.
- `node --run check`: passed.
- `node --run test:control-plane`: 153/153 passed.
- `node --run test:legacy`: 260/260 passed, including the new four tests.
- `node --run build`: passed.
- `check_project_docs.py`: passed.
- `check_doc_drift.py --task-id 20260902-registration-invalid-params-59f94692`: passed.
- Verification used the bundled Node runtime and a temporary ignored `node_modules` symlink to the existing dependency tree because Node was not on the isolated shell `PATH`.
## Follow-ups
- Integrate this isolated feature change with the concurrent dashboard layout work, then restart or redeploy the standard service only under separate explicit authorization before expecting the live `/accounts` page to change.
## Promotion Candidates
- None recorded.
## Supporting Records
- [Account registration password validation evidence](../../50-evidence/topics/20260902-registration-invalid-params-59f94692__account-registration-password-validation.md)