fix(signin): exempt /signin chooser from silent auto-login - #2607
Merged
Merged
Conversation
The /signin IdP chooser (shipped in 746f0df) is where a deliberate profile-click lands so the user can pick an identity provider. But maybeAutoLogin() runs on every page via the header partial and only exempts the homepage (/). For any returning visitor (localStorage['auth.returning']==='1', durable across sessions), landing on /signin triggers an immediate location.replace('/login?...') before the chooser renders, silently SSO-ing them in and skipping the choice entirely. The chooser was effectively unreachable for its intended audience. Exempt /signin (trailing-slash tolerant) from maybeAutoLogin the same way / is exempt, so the chooser always renders when the user asked for it.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
The
/signinIdP chooser (shipped in746f0df37, deployed to DEV today) is unreachable for its intended audience. Clicking the shellbar profile while anonymous routes to/signinso the user can pick an identity provider — but the chooser never renders. Returning visitors are silently SSO-ed straight through to/login, skipping the choice entirely. Reported on DEV: "I'm not getting the login type selection screen" / "profile click logs me in silently even in incognito."Root cause
maybeAutoLogin()(header.html) runs on every page via the header partial. It only exempts the homepage (/). For any returning visitor —localStorage['auth.returning'] === '1', which is durable across sessions and set on first successful auth — landing on/signintriggers an immediatelocation.replace('/login?...')before the chooser HTML paints.The
746f0df37commit wired profile-click →/signinbut didn't exempt/signinfrom the silent auto-login that fires on load, so the two paths fight and auto-login always wins.Fix
Exempt
/signin(trailing-slash tolerant) frommaybeAutoLoginthe same way/is exempt. One line. The deliberate chooser now always renders;maybeAutoLogin's silent returning-visitor SSO (#1689) still fires on all other pages unchanged.Verification
/signincurrently serves 200 with both chooser buttons — the page itself is fine; the bug is the client-side auto-bounce on load./signinfalls through thereturnand the chooser paints instead of redirecting.🤖 Generated with Claude Code