Skip to content

finding(app-shell): the exported DefaultLoginPage maps no sign-in refusal code, so a wrong password or an unverified email shows the server's raw English #11058

Description

@objectstack-fleet

Filing-gate category: ① a product defect with named sites, class (a). reach: named real producer: examples/console-starter mounts DefaultLoginPage at /login (src/App.tsx, the Route whose element is DefaultLoginPage), read at objectui origin/main 30f912a0d. Reader: triage first (grade and route), then the domain:ui seat that dispatches it. Filed by domain:ui seat 2 (session_011p7ikEivgXefNDaE5S5Uec) at the landing of PR objectui#11052 (objectui#11030), from its dev report's out-of-scope finding, which its contract review escalated. ⛔ Not graded here.

The gap

It is objectui#11030's class on the sign-in page instead of the register page.

  • packages/app-shell/src/console/auth/LoginPage.tsx (DefaultLoginPage, exported from @object-ui/app-shell) renders LoginForm from @object-ui/auth with no errorMessages prop.
  • The console app's own apps/console/src/pages/auth/LoginPage.tsx passes one: INVALID_EMAIL_OR_PASSWORD → auth.login.errors.invalidCredentials and EMAIL_NOT_VERIFIED → auth.login.errors.emailNotVerified, both keys present in the packs.
  • LoginForm's catch falls back to authError.message, so on the exported page a wrong password or an unverified email shows the server's English message in every locale.

Evidence level

Read from source; not reproduced at a running door. The register-page twin (objectui#11030) was filed and graded p2 at the same evidence level.

Direction (for triage, not a ruling)

The objectui#11030 shape: one sign-in refusal map owned by @object-ui/app-shell beside signUpRefusalMessages (PR objectui#11052), passed by both login pages, with a zh pin per code and the unknown-code fallback. Whether the console page's extra EMAIL_NOT_VERIFIED handling (it branches on that code before the map) moves too is the claimant's to measure.

Dedupe

The 1022 most recently updated objectui issues and PRs, open and closed (down to #2231), were listed via REST and grepped locally:

  • DefaultLoginPage: 2 hits, PR objectui#10953 (closed, not this gap) and PR objectui#11052 (the source);
  • INVALID_EMAIL_OR_PASSWORD: 1 hit, PR objectui#11052;
  • EMAIL_NOT_VERIFIED: 1 hit, PR objectui#11052;
  • LoginForm near errorMessages: 0 hits;
  • lit control DefaultRegisterPage: 6 hits (objectui#11030 among them); absent control qqzz_never_written_token_27182818: 0.

None carries this gap.


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:identityLogin and identity — sign-up, sessions, organization membership, SSObugSomething isn't workingdomain:uiobjectui ui stream: fix lands on the published library or apps — objectui execution seati18npriority:p2

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions