Sure there’s a great reason why the code was written such that regardless of length of username you may allow some length can magically skip the password phase.
And these are the companies people sit in the middle doing SSO and MFA with. Or in other words. They’re a bloody vulnerability you’re adding to your stack you thought were helping you with identity and security management.