Skip to content

fix(auth): cap new-password inputs at 72 bytes and install dev extras - #529

Open
vidit-admin wants to merge 2 commits into
mainfrom
fix/password-maxlength-make-install
Open

vidit-admin wants to merge 2 commits into
mainfrom
fix/password-maxlength-make-install

Conversation

@vidit-admin

Copy link
Copy Markdown
Member

Summary

  • Password forms (settings change-password, register, reset-password) set maxLength from a new PASSWORD_MAX_BYTES constant in lib/auth.ts and check the UTF-8 byte count before submit, so multibyte input gets a plain message instead of a 422.
  • schemas/auth.NewPassword drops max_length: an over-long ASCII password now gets the byte-limit message (password_too_long) instead of Pydantic's generic "String should have at most 72 characters". New backend test covers it.
  • PASSWORD_MAX_BYTES is registered as a hand-kept mirror in docs/engineering.md, with a pointer comment on each side.
  • make install runs uv sync --all-extras (CI adds --frozen), so pytest is installed and make test runs on a fresh machine. README troubleshooting line updated.

maxLength counts UTF-16 units, which never outnumber UTF-8 bytes, so it never blocks a valid password; the byte check covers the rest.

Test plan

  • make test: 1699 passed
  • backend ruff, ruff format, mypy, vulture: clean
  • frontend npm run lint (0 errors), npx tsc --noEmit, npm test (900 passed), make hygiene: clean
  • Browser on /settings: typing 88 characters stops at 72; 40 accented letters show the byte-limit message without a request

🤖 Generated with Claude Code

vidit-admin and others added 2 commits October 4, 2026 18:18
Password forms (settings, register, reset) set maxLength from a new
PASSWORD_MAX_BYTES mirror and check the UTF-8 byte count before submit.
NewPassword drops max_length so an over-long ASCII password gets the
byte-limit message instead of the generic Pydantic one.

make install runs uv sync --all-extras so pytest is present.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: vidit-admin <admin@vidit.app>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: vidit-admin <admin@vidit.app>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant