Skip to content

fix(signin): exempt /signin chooser from silent auto-login - #2607

Merged
jung-thomas merged 1 commit into
DEVfrom
fix/signin-chooser-autologin-exempt
Oct 2, 2026
Merged

jung-thomas merged 1 commit into
DEVfrom
fix/signin-chooser-autologin-exempt

Conversation

@jung-thomas

Copy link
Copy Markdown
Contributor

Problem

The /signin IdP chooser (shipped in 746f0df37, deployed to DEV today) is unreachable for its intended audience. Clicking the shellbar profile while anonymous routes to /signin so the user can pick an identity provider — but the chooser never renders. Returning visitors are silently SSO-ed straight through to /login, skipping the choice entirely. Reported on DEV: "I'm not getting the login type selection screen" / "profile click logs me in silently even in incognito."

Root cause

maybeAutoLogin() (header.html) runs on every page via the header partial. It only exempts the homepage (/). For any returning visitor — localStorage['auth.returning'] === '1', which is durable across sessions and set on first successful auth — landing on /signin triggers an immediate location.replace('/login?...') before the chooser HTML paints.

The 746f0df37 commit wired profile-click → /signin but didn't exempt /signin from the silent auto-login that fires on load, so the two paths fight and auto-login always wins.

Fix

Exempt /signin (trailing-slash tolerant) from maybeAutoLogin the same way / is exempt. One line. The deliberate chooser now always renders; maybeAutoLogin's silent returning-visitor SSO (#1689) still fires on all other pages unchanged.

Verification

  • Deployed /signin currently serves 200 with both chooser buttons — the page itself is fine; the bug is the client-side auto-bounce on load.
  • After this change, a returning visitor hitting /signin falls through the return and the chooser paints instead of redirecting.

🤖 Generated with Claude Code

The /signin IdP chooser (shipped in 746f0df) is where a deliberate
profile-click lands so the user can pick an identity provider. But
maybeAutoLogin() runs on every page via the header partial and only
exempts the homepage (/). For any returning visitor
(localStorage['auth.returning']==='1', durable across sessions), landing
on /signin triggers an immediate location.replace('/login?...') before
the chooser renders, silently SSO-ing them in and skipping the choice
entirely. The chooser was effectively unreachable for its intended
audience.

Exempt /signin (trailing-slash tolerant) from maybeAutoLogin the same
way / is exempt, so the chooser always renders when the user asked for
it.
@jung-thomas
jung-thomas merged commit a7a53dd into DEV Oct 2, 2026
5 checks passed
@jung-thomas
jung-thomas deleted the fix/signin-chooser-autologin-exempt branch October 2, 2026 21:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant