Skip to content

bug: Login fails due to untrimmed whitespace in email/username #1900

Description

@Ankitsinghsisodya

Describe the bug
The login functionality on the CMS does not strip leading or trailing whitespace from the user input fields (specifically email/username). If a user accidentally includes a space (often happening during copy-pasting or auto-fill), the validation fails or the backend rejects the credentials, leading to a frustrating user experience.

To Reproduce
Steps to reproduce the behavior:

  1. Go to the CMS login page.
  2. Enter a valid registered email address but add a trailing space (e.g., "user@example.com ").
  3. Enter the correct password.
  4. Click the Login button.
  5. See error: The system rejects the login attempt (likely due to an "Invalid credentials" error or similar validation failure), even though the core credentials are correct.

Expected behavior
The application should automatically trim() the input values for the email/username fields before sending the request to the backend. This ensures that accidental whitespace does not prevent a valid user from logging in.

Info (please complete the following information):

  • Browser: [e.g. Chrome, Firefox]
  • Version: [e.g. Latest]

Additional context
This is a common UX issue when users copy-paste their email addresses from other sources or when mobile keyboards auto-insert spaces.
Suggested Fix: Apply .trim() to the input string in the onChange handler or just before the form submission logic.

Activity

  1. changed the title [-]bug:[/-] [+]bug: Login fails due to untrimmed whitespace in email/username[/+] on Dec 17, 2025
  2. chandu14321 commented on Aug 4, 2026

    @chandu14321

    I'd like to work on this issue.

    Approach:

    • I saw PR Fix auth login logic: avoid password rehashing and token-gated auth #1902 which attempted a fix and reported that trim() alone wasn't enough (they hit a 401 even after trimming) — but that PR also expanded into unrelated auth/bcrypt/token changes and reported the 401 was actually caused by a missing DATABASE_URL locally, not the trim fix itself.
    • My plan is to keep this scoped strictly to the original issue: trim the email/username value right before the login request is sent (submit handler), and check if the shared validation schema (if one exists, e.g. Zod) also needs .trim() for consistency.
    • I'll verify locally with a properly configured DATABASE_URL to rule out false 401s, and test with leading/trailing spaces to confirm the fix actually resolves the reported bug.
    • I won't touch auth/bcrypt/token logic — that's outside the scope of this issue.

    Happy to adjust based on maintainer feedback.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions