fix: validate account creation password
This commit is contained in:
1 parent
3ed3af1feb
commit
203bfb3246
5 files changed
+249
-10
No files matched your search
+27
@@ -0,0 +1,27 @@
|
||||
# Account Registration Password Validation Evidence
|
||||
|
||||
## Source
|
||||
|
||||
- Read-only inspection on 2026-09-02 of the standard service's privacy-safe structured diagnostics.
|
||||
- Active account form, API request builder, `accountCreateSchema`, authentication validation, and account authorization tests at base commit `3ed3af1feb503358b98fb57d3e8d97ab59d98129`.
|
||||
|
||||
## Finding
|
||||
|
||||
- The two recent `http.request.invalid` events both reported only the validation path `password`.
|
||||
- The server contract requires an initial password length of 12–512 characters.
|
||||
- The HTML field declared the same `minlength` and `maxlength`, but the account form used `novalidate` and the JavaScript request path did not perform its own validation before calling `/api/accounts`.
|
||||
- Therefore a short initial password reached server-side Zod validation and the UI displayed the generic response “请求参数不符合要求。” instead of the actual password requirement.
|
||||
|
||||
## Privacy And Safety
|
||||
|
||||
- Only diagnostic event type and validation field paths were extracted.
|
||||
- No password, account name, request body, environment file, database row, or other business/user content was read or stored.
|
||||
- No live account request or runtime mutation was performed.
|
||||
|
||||
## Confidence
|
||||
|
||||
- High. Runtime field-path evidence, the active form behavior, and the server schema all identify the same password-length mismatch.
|
||||
|
||||
## Stale Trigger
|
||||
|
||||
- Reassess if the password contract, account form submission flow, or generic API validation response changes.
|
||||
Reference in new issue
Block a user