fix: simplify account password flow
This commit is contained in:
1 parent
203bfb3246
commit
df65e9f517
9 files changed
+118
-131
No files matched your search
+10
-3
@@ -8,10 +8,17 @@
|
||||
## Finding
|
||||
|
||||
- The two recent `http.request.invalid` events both reported only the validation path `password`.
|
||||
- The server contract requires an initial password length of 12–512 characters.
|
||||
- At the inspected base commit, the server contract required an initial password length of 12–512 characters.
|
||||
- The HTML field declared the same `minlength` and `maxlength`, but the account form used `novalidate` and the JavaScript request path did not perform its own validation before calling `/api/accounts`.
|
||||
- Therefore a short initial password reached server-side Zod validation and the UI displayed the generic response “请求参数不符合要求。” instead of the actual password requirement.
|
||||
|
||||
## User Decision And Resolution
|
||||
|
||||
- The user explicitly superseded the original password-length contract: all password entry points now require only a non-empty value and impose no application-level minimum or maximum length.
|
||||
- The user also directed removal of the first-login forced-password-change flow. The UI option, session flag, route gate, account badge, and forced panel state were removed; voluntary password changes remain available.
|
||||
- The historical `must_change_password` database column is retained only for schema compatibility and is ignored by runtime authorization. Password writes clear it to `false`.
|
||||
- This change was implemented and verified in an isolated feature worktree. No running service was restarted and no live account or database row was mutated.
|
||||
|
||||
## Privacy And Safety
|
||||
|
||||
- Only diagnostic event type and validation field paths were extracted.
|
||||
@@ -20,8 +27,8 @@
|
||||
|
||||
## Confidence
|
||||
|
||||
- High. Runtime field-path evidence, the active form behavior, and the server schema all identify the same password-length mismatch.
|
||||
- High. Runtime field-path evidence and the inspected base contract identify the original mismatch; the replacement behavior is directly confirmed by the user's product decision and regression coverage.
|
||||
|
||||
## Stale Trigger
|
||||
|
||||
- Reassess if the password contract, account form submission flow, or generic API validation response changes.
|
||||
- Reassess if a future product decision introduces password policy requirements, a forced-password-change lifecycle, or a replacement for the compatibility column.
|
||||
Reference in new issue
Block a user