fix: simplify account password flow

This commit is contained in:
inman committed 2026-09-02 11:15:30 +08:00
1 parent 203bfb3246
commit df65e9f517
9 files changed
+118 -131

No files matched your search

@@ -8,10 +8,17 @@
## Finding
- The two recent `http.request.invalid` events both reported only the validation path `password`.
- The server contract requires an initial password length of 12–512 characters.
- At the inspected base commit, the server contract required an initial password length of 12–512 characters.
- The HTML field declared the same `minlength` and `maxlength`, but the account form used `novalidate` and the JavaScript request path did not perform its own validation before calling `/api/accounts`.
- Therefore a short initial password reached server-side Zod validation and the UI displayed the generic response “请求参数不符合要求。” instead of the actual password requirement.
## User Decision And Resolution
- The user explicitly superseded the original password-length contract: all password entry points now require only a non-empty value and impose no application-level minimum or maximum length.
- The user also directed removal of the first-login forced-password-change flow. The UI option, session flag, route gate, account badge, and forced panel state were removed; voluntary password changes remain available.
- The historical `must_change_password` database column is retained only for schema compatibility and is ignored by runtime authorization. Password writes clear it to `false`.
- This change was implemented and verified in an isolated feature worktree. No running service was restarted and no live account or database row was mutated.
## Privacy And Safety
- Only diagnostic event type and validation field paths were extracted.
@@ -20,8 +27,8 @@
## Confidence
- High. Runtime field-path evidence, the active form behavior, and the server schema all identify the same password-length mismatch.
- High. Runtime field-path evidence and the inspected base contract identify the original mismatch; the replacement behavior is directly confirmed by the user's product decision and regression coverage.
## Stale Trigger
- Reassess if the password contract, account form submission flow, or generic API validation response changes.
- Reassess if a future product decision introduces password policy requirements, a forced-password-change lifecycle, or a replacement for the compatibility column.