Homestyx hydra
Diffusion hydra 6f3bd13cf5da

Begin adding more guidance to the "One-Time Login" flow

Description

Begin adding more guidance to the "One-Time Login" flow

Summary:
Ref T13244. See PHI774. If an install does not use password auth, the "one-time login" flow (via "Welcome" email or "bin/auth recover") is pretty rough. Current behavior:

  • If an install uses passwords, the user is prompted to set a password.
  • If an install does not use passwords, you're dumped to /settings/external/ to link an external account. This is pretty sketchy and this UI does not make it clear what users are expected to do (link an account) or why (so they can log in).

Instead, improve this flow:

  • Password reset flow is fine.
  • (Future Change) If there are external linkable accounts (like Google) and the user doesn't have any linked, I want to give users a flow like a password reset flow that says "link to an external account".
  • (This Change) If you're an administrator and there are no providers at all, go to "/auth/" so you can set something up.
  • (This Change) If we don't hit on any other rules, just go home?

This may be tweaked a bit as we go, but basically I want to refine the "/settings/external/" case into a more useful flow which gives users more of a chance of surviving it.

Test Plan: Logged in with passwords enabled (got password reset), with nothing enabled as an admin (got sent to Auth), and with something other than passwords enabled (got sent home).

Reviewers: amckinley

Reviewed By: amckinley

Maniphest Tasks: T13244

Differential Revision: https://secure.phabricator.com/D20094

Details

Provenance
epriestleyAuthored on Feb 5 2019, 8:22 AM
sirocylPushed on Oct 16 2024, 5:49 AM
Parents
R1:03eb989fd875: Give Duo MFA a stronger hint if users continue without answering the challenge
Branches
Unknown
Tags
Unknown

Event Timeline