Skip to content

Make admin email login case-insensitive - #2845

Open
wakqasahmed wants to merge 1 commit into
area17:3.xfrom
wakqasahmed:fix/case-insensitive-admin-email-login
Open

wakqasahmed wants to merge 1 commit into
area17:3.xfrom
wakqasahmed:fix/case-insensitive-admin-email-login

Conversation

@wakqasahmed

Copy link
Copy Markdown

Description

LoginController::credentials() passes the raw email input straight to the auth guard, so login is case-sensitive whenever the email column's collation is case-sensitive (e.g. Postgres, or MySQL with a _bin/case-sensitive collation) — a user created as User@example.com can't log in as user@example.com. Changed credentials() to match on LOWER(email) via a closure credential (Laravel's EloquentUserProvider has supported closures for custom query building since Laravel 8), so the match no longer depends on collation. Added an integration test that forces a case-sensitive collation on email for the duration of the test and restores it after — the default collation in this repo's own MySQL test DB is already case-insensitive, so a plain "log in with different case" test wouldn't have actually caught the regression.

Used AI assistance (Claude) to write and test this; reviewed the diff and ran the full LoginTest suite plus php-cs-fixer before opening.

Related Issues

Fixes #2789

@CLAassistant

CLAassistant commented Sep 4, 2026 •

Copy link
Copy Markdown

CLA assistant check
All committers have signed the CLA.

@wakqasahmed
wakqasahmed force-pushed the fix/case-insensitive-admin-email-login branch from cf958ea to dae4f9d Compare September 4, 2026 13:23
@wakqasahmed

Copy link
Copy Markdown
Author

Hi @ifox — noticed this PR doesn't have a reviewer assigned yet — it's been sitting for a while, CI is green and it's mergeable. Would you (or whoever's best placed) be able to take a look, or point me to who should? Thanks!

@wakqasahmed

Copy link
Copy Markdown
Author

Hi @ifox — circling back on this one — still no reviewer assigned, quiet for a while since the last activity. No pressure, just don't want it to get lost.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Admin user authentication treats email addresses as case-sensitive

2 participants