fix: normalize username and password with NFC in login flow

precheckLogin already normalized the username with NFC, but the
NextAuth credentials authorize handler only trimmed it. This caused a
mismatch for accounts with accented/non-ASCII usernames: the precheck
passed while the actual sign-in lookup found no user and returned
'invalid username or password'.

Also normalize the password to NFC in both the precheck and the
authorize handler to match how register.ts hashes it.
This commit is contained in:
openhands committed 2026-08-27 15:09:43 +02:00
1 parent d5eadeb3a7
commit ac5cd6bc3f
2 files changed
+5 -3

No files matched your search

+1 -1
View File
@@ -27,7 +27,7 @@ export async function precheckLogin(
const u = String(username ?? "")
.normalize("NFC")
.trim();
const p = String(password ?? "");
const p = String(password ?? "").normalize("NFC");
if (!u || !p) return "invalid";
const ip = await clientIp();
+4 -2
View File
@@ -149,8 +149,10 @@ export const { handlers, signOut, auth } = NextAuth({
code: { label: "2FA code", type: "text" },
},
authorize: async (credentials) => {
const username = String(credentials?.username ?? "").trim();
const password = String(credentials?.password ?? "");
const username = String(credentials?.username ?? "")
.normalize("NFC")
.trim();
const password = String(credentials?.password ?? "").normalize("NFC");
if (!username || !password) return null;
const ip = await clientIp();