My biggest question here is are they not just feeding the input into a hash function, why can't it be longer than 20 characters?
CREATE TABLE passwords (
email VARCHAR(MAX),
password VARCHAR(20) UNIQUE -- unique passwords are more secure.
-- NOTE: "20" here because we used to use SHA1 hashes
-- but there was an issue with storing binary in CP437
-- so we just renamed the field.
)But 20 characters is simply ridiculous.
The person who wrote it just came up with 20 in the moment and forgot to go check, something everyone has done a hundred times.
I've probably never worked on a single system where the html validation, http server validation, and database constraint were synchronized on username max length. You choose a placeholder, an even number between 10 and 16, then forget to ever check.