Indeed, that's because we use $sanitize on the password. This should be disabled when using LDAP authentication. I'm thinking this should be done for the username as well.
@youlu-cn can you try with the image portainer/portainer:pr1136 (available on Linux amd64 only) ?
@deviantony it works