fix: validate account creation password

This commit is contained in:
inman committed 2026-09-02 11:00:13 +08:00
1 parent 3ed3af1feb
commit 203bfb3246
5 files changed
+249 -10

No files matched your search

@@ -0,0 +1,27 @@
# Account Registration Password Validation Evidence
## Source
- Read-only inspection on 2026-09-02 of the standard service's privacy-safe structured diagnostics.
- Active account form, API request builder, `accountCreateSchema`, authentication validation, and account authorization tests at base commit `3ed3af1feb503358b98fb57d3e8d97ab59d98129`.
## Finding
- The two recent `http.request.invalid` events both reported only the validation path `password`.
- The server contract requires an initial password length of 12–512 characters.
- The HTML field declared the same `minlength` and `maxlength`, but the account form used `novalidate` and the JavaScript request path did not perform its own validation before calling `/api/accounts`.
- Therefore a short initial password reached server-side Zod validation and the UI displayed the generic response “请求参数不符合要求。” instead of the actual password requirement.
## Privacy And Safety
- Only diagnostic event type and validation field paths were extracted.
- No password, account name, request body, environment file, database row, or other business/user content was read or stored.
- No live account request or runtime mutation was performed.
## Confidence
- High. Runtime field-path evidence, the active form behavior, and the server schema all identify the same password-length mismatch.
## Stale Trigger
- Reassess if the password contract, account form submission flow, or generic API validation response changes.