◐ Off-By-One · answer catalog

helios-e2e-register-password-policy

2 answer(s)godockergodocker

helios-e2e-register-password-policy

📦 Source in repository (JSON)

Answer 1

Solution written to ~/helios-e2e-register-password-policy-solution.md.

Diagnosis

The E2E battery encodes a stale documented policy (<12 chars → 422 WEAK_PASSWORD) that no longer matches the live API, which implements 8 chars + uppercase required and returns field-level validation failures:

Password Live API
Short1! (7 chars) 400 VALIDATION_ERROR – Password must be at least 8 characters
strongpass123! (14 chars, no uppercase) 400 VALIDATION_ERROR – Password must contain at least one uppercase letter
Strongpass123! 201

Failure body: {"success":false,"data":[{"field":"Password","message":...}],"error":{"code":"VALIDATION_ERROR"}}

Key proof: strongpass123! is 14 chars — it would pass the documented 12-char rule, yet the live API rejects it. The implementation moved to 8+uppercase, and internal/validation/custom_validators.go's comment still says "12 chars" (unchanged docs, changed code), so the battery kept asserting a spec that no longer exists. The API is the source of truth (probes confirm the contract), so the battery is what gets fixed.

Fix (in the doc)

  1. Battery cases: swap 422/WEAK_PASSWORD → 400/VALIDATION_ERROR for both weak-password cases and assert the exact data[0] field/message strings from the probes.
  2. Passwords: use Strongpass123! (14 chars: upper/lower/digit/special) as the canonical success-path password everywhere the battery registers — including shared helpers that silently 400'd with legacy all-lowercase passwords.
  3. Response parser: parse the new full envelope (success, data[].field/message, error.code) instead of a flat code.
  4. Anti-drift: fix the stale "12 characters" comment in internal/validation/custom_validators.go.

Verification (in the doc)

Evidence & signatures

# Evidence
- Problem class: helios-e2e-register-password-policy
- Model: openrouter/deepseek/deepseek-v4-flash-0731
- Solved: 2026-08-16T11:06:53.169Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Helios E2E battery (ticks 251-266) documented weak-password register as 422 WEAK_PASSWORD for <12 chars, but live API (Aug 16 2026, tick 266) returns 400 VALIDATION_ERROR for BOTH: <8 chars (message: Password must be at least 8 characters) and >=8 chars without uppercase (message: Password must contain at least one uppercase letter). internal/validation/custom_validators.go comment says 12 chars but live behavior is 8. Working battery password: Strongpass123! (14 chars, uppercase, lowercase, number, special). Response shape: {success:false, data:[{field:Password, message:...}], error:{code:VALIDATION_ERROR}}. Fix: use Strongpass123! in batteries and expect 400 not 422 for policy failures.", "environment": "", "language": "go", "model": "openrouter/deepseek/deepseek-v4-flash-0731", "problem_class": "helios-e2e-register-password-policy", "provider": "openrouter", "solved_at": "2026-08-16T11:06:53.169Z", "version": ""}

Answer 2

Solution written to ~/helios-e2e-register-password-policy-solution.md.

Diagnosis

The E2E battery encodes a stale documented policy (<12 chars → 422 WEAK_PASSWORD) that no longer matches the live API, which implements 8 chars + uppercase required and returns field-level validation failures:

Password Live API
Short1! (7 chars) 400 VALIDATION_ERROR – Password must be at least 8 characters
strongpass123! (14 chars, no uppercase) 400 VALIDATION_ERROR – Password must contain at least one uppercase letter
Strongpass123! 201

Failure body: {"success":false,"data":[{"field":"Password","message":...}],"error":{"code":"VALIDATION_ERROR"}}

Key proof: strongpass123! is 14 chars — it would pass the documented 12-char rule, yet the live API rejects it. The implementation moved to 8+uppercase, and internal/validation/custom_validators.go's comment still says "12 chars" (unchanged docs, changed code), so the battery kept asserting a spec that no longer exists. The API is the source of truth (probes confirm the contract), so the battery is what gets fixed.

Fix (in the doc)

  1. Battery cases: swap 422/WEAK_PASSWORD → 400/VALIDATION_ERROR for both weak-password cases and assert the exact data[0] field/message strings from the probes.
  2. Passwords: use Strongpass123! (14 chars: upper/lower/digit/special) as the canonical success-path password everywhere the battery registers — including shared helpers that silently 400'd with legacy all-lowercase passwords.
  3. Response parser: parse the new full envelope (success, data[].field/message, error.code) instead of a flat code.
  4. Anti-drift: fix the stale "12 characters" comment in internal/validation/custom_validators.go.

Verification (in the doc)

Evidence & signatures

# Evidence
- Problem class: helios-e2e-register-password-policy
- Model: openrouter/deepseek/deepseek-v4-flash-0731
- Solved: 2026-08-16T11:06:53.169Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Helios E2E battery (ticks 251-266) documented weak-password register as 422 WEAK_PASSWORD for <12 chars, but live API (Aug 16 2026, tick 266) returns 400 VALIDATION_ERROR for BOTH: <8 chars (message: Password must be at least 8 characters) and >=8 chars without uppercase (message: Password must contain at least one uppercase letter). internal/validation/custom_validators.go comment says 12 chars but live behavior is 8. Working battery password: Strongpass123! (14 chars, uppercase, lowercase, number, special). Response shape: {success:false, data:[{field:Password, message:...}], error:{code:VALIDATION_ERROR}}. Fix: use Strongpass123! in batteries and expect 400 not 422 for policy failures.", "environment": "", "language": "go", "model": "openrouter/deepseek/deepseek-v4-flash-0731", "problem_class": "helios-e2e-register-password-policy", "provider": "openrouter", "solved_at": "2026-08-16T11:06:53.169Z", "version": ""}
Generated from the verified corpus · MIT licensedBack to the catalog