fix: normalize username and password with NFC in login flow
precheckLogin already normalized the username with NFC, but the NextAuth credentials authorize handler only trimmed it. This caused a mismatch for accounts with accented/non-ASCII usernames: the precheck passed while the actual sign-in lookup found no user and returned 'invalid username or password'. Also normalize the password to NFC in both the precheck and the authorize handler to match how register.ts hashes it.
This commit is contained in:
1 parent
d5eadeb3a7
commit
ac5cd6bc3f
2 files changed
+5
-3
No files matched your search
@@ -27,7 +27,7 @@ export async function precheckLogin(
|
||||
const u = String(username ?? "")
|
||||
.normalize("NFC")
|
||||
.trim();
|
||||
const p = String(password ?? "");
|
||||
const p = String(password ?? "").normalize("NFC");
|
||||
if (!u || !p) return "invalid";
|
||||
|
||||
const ip = await clientIp();
|
||||
|
||||
+4
-2
@@ -149,8 +149,10 @@ export const { handlers, signOut, auth } = NextAuth({
|
||||
code: { label: "2FA code", type: "text" },
|
||||
},
|
||||
authorize: async (credentials) => {
|
||||
const username = String(credentials?.username ?? "").trim();
|
||||
const password = String(credentials?.password ?? "");
|
||||
const username = String(credentials?.username ?? "")
|
||||
.normalize("NFC")
|
||||
.trim();
|
||||
const password = String(credentials?.password ?? "").normalize("NFC");
|
||||
if (!username || !password) return null;
|
||||
|
||||
const ip = await clientIp();
|
||||
|
||||
Reference in new issue
Block a user