From ac5cd6bc3f6e28122ddc579ce011ae825aae8c36 Mon Sep 17 00:00:00 2001 From: openhands Date: Thu, 27 Aug 2026 15:09:43 +0200 Subject: [PATCH] fix: normalize username and password with NFC in login flow precheckLogin already normalized the username with NFC, but the NextAuth credentials authorize handler only trimmed it. This caused a mismatch for accounts with accented/non-ASCII usernames: the precheck passed while the actual sign-in lookup found no user and returned 'invalid username or password'. Also normalize the password to NFC in both the precheck and the authorize handler to match how register.ts hashes it. --- src/actions/auth-precheck.ts | 2 +- src/lib/auth.ts | 6 ++++-- 2 files changed, 5 insertions(+), 3 deletions(-) diff --git a/src/actions/auth-precheck.ts b/src/actions/auth-precheck.ts index b5eee29a35..3c35350309 100644 --- a/src/actions/auth-precheck.ts +++ b/src/actions/auth-precheck.ts @@ -27,7 +27,7 @@ export async function precheckLogin( const u = String(username ?? "") .normalize("NFC") .trim(); - const p = String(password ?? ""); + const p = String(password ?? "").normalize("NFC"); if (!u || !p) return "invalid"; const ip = await clientIp(); diff --git a/src/lib/auth.ts b/src/lib/auth.ts index 0521ea5d0d..594b06acae 100644 --- a/src/lib/auth.ts +++ b/src/lib/auth.ts @@ -149,8 +149,10 @@ export const { handlers, signOut, auth } = NextAuth({ code: { label: "2FA code", type: "text" }, }, authorize: async (credentials) => { - const username = String(credentials?.username ?? "").trim(); - const password = String(credentials?.password ?? ""); + const username = String(credentials?.username ?? "") + .normalize("NFC") + .trim(); + const password = String(credentials?.password ?? "").normalize("NFC"); if (!username || !password) return null; const ip = await clientIp();