- User unable to log into Vanguard web account for a year due to password mismatch.
- Password reset form had input field with `maxlength="20"`, truncating pasted passwords longer than 20 characters.
- Login page password field lacked the `maxlength` restriction, causing full password input.
- The 26-character password was saved as 20 characters during reset, but entered fully at login.
- User advises against using `maxlength` on password fields; recommends backend or JavaScript-based length validation.