Add an explicit non-empty check before encrypting user-submitted email/password fields in the create and update user routes, so a request that bypasses the HTML `required` attribute gets a clean 400 instead of an unhandled ValueError from CredentialCipher.encrypt propagating as a 500. Applies to all four credential fields on create, and to the two email fields on update (the password-blank- means-keep-existing behavior on update is unchanged). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
11 KiB
11 KiB