Auth enumeration
An authentication error message that distinguishes a wrong password from an unknown account is an account-enumeration oracle: each distinct message is a bit of information about whether an address is registered. The messages are written for helpfulness one at a time, and no single one looks like a disclosure - the leak exists only across the set, which is why it survives review and why the safe wording has to be a fixed list rather than a judgement made per message.
Resurfaces when
- writing error messages for a sign-in or sign-up form
- deciding how much detail a failed login should return
- reviewing auth flows for account enumeration
The lesson’s retrieval contract, weighted three times heavier than its body. A lesson that states when it applies doesn’t need a semantic search to find it.
The lesson
Use only the safe messages listed in architecture/routing.md
The failure that taught it
Error messages must not reveal whether email or password is wrong
How to apply it
Use only the safe messages listed in architecture/routing.md
Where this claim comes from
- Lesson
Auth enumeration
- Distillationmechanism stated
Written from the mechanism, not the incident — which is what lets it transfer to code sharing nothing with the original.
- Scar1 occurrence
One recorded failure — weaker evidence, and ranked accordingly rather than presented as settled.
- Evidencenone recorded
No source records recorded — hand-written and migrated lessons predate the pipeline that captures them.
What happened when it was used
- 0
- retrieved
- 0
- acted on
- 0
- held up
- 0
- did not hold up
Never retrieved. A new lesson starts at a neutral 1.0, deliberately — so learning something new cannot bury everything learned next.