Topic: Announcement: New Login Flow

Posted
by Mike
Mike
joined
posted

Today I changed the login and register flow from the ground up, moving away from passwords. While it is still possible to login with username/mail and password, the new preferred way is to just enter your username or password and then log in using a code that we send you via email.

This simplifies many things going forward. Let me know what you think about it, or which ways other ways of logging in you would prefer.

Mike
joined
posted

And sadly, you'll need to re-login once again - this is the final change, hopefully.

For the tech nerds: I switched from access tokens stored in the browser (localStore) to a more safe approach, but that means that all your tokens are no longer valid.

Let me know if you have any problems logging in! Obviously not in this forum, but you can always use the feedback form, in which case you'll need to mention your username, so that I know who you are :-)

Mike
joined
posted

I'm very sorry, but there's another important change which will force everyone to re-login. This time it is the token rotation which I added for safety reasons. Please bear with me :-)

Mike
joined
posted , edited

Today I fixed a bug that could cause users to get logged out again upon returning to the website. If you encounter any problems, please let me know! Automatic logout should only happen after 30+ days of inactivity.

bartyMJ
joined
posted

Not exactly a 'problem' but just for info I have noticed that now on the first visit to the site since the login change the recommended releases seem to be random & include things I have rated previously, and refreshing the main page then reverts them back to 'normal'

Mike
joined
posted

Thanks for the feedback! Definitely a bug we need to fix.

Mike
joined
posted

I have the suspicion that the 30 day expiry of the sessions doesn't yet work properly ... I had to log in again after a few hours of inactivity on my mobile device. Looking into it ... like I said above, you should not have to log in again frequently on the same device.

anonymous user
posted , edited

i'm not doing the 2fa login. please keep passwords.

Mike
joined
posted

It's not a two-factor login, for that we would need to pin logins to devices.

Why are you against the email code flow, what is your reasoning? Feel free to answer via PM (feedback form), if you don't want to share it publicly, but I'd like to understand it better.

In any case, I am not planning to retire the old password mechanism any time soon. I had to remove the Google login because I was using a complicated library that is no longer maintained properly and was becoming an obstacle to security patches. I might add back the Google login, or even a list of other Oauth Providers in the future.

Mike
joined
posted

Incidentally: Since we are no longer storing any login-related information in the browser local storage, those of you who are concerned about privacy will be glad to know that the browser now properly "forgets" you if you delete all the cookies related to this website's domain. We now use just two simple, http-only cookies that get set once you log in, which is the current best practice.

You need to sign in to post replies.