3 ms·
This pattern is used for SSO. It doesn't make a lot of sense to request a password from a user who is using a SSO solution. The issue is the website needs to do
by humblebee 9y ago
This pattern is used for SSO. It doesn't make a lot of sense to request a password from a user who is using a SSO solution. The issue is the website needs to do a look up on the username to determine which SSO solution the user might be using.
There might be a better pattern for this, such as making the determination through a xhr request when the username field loses focus.
- CydeWeys 9y agoAnother good thing to do in combination with that is to store the SSO provider locally (cookie/local storage, whatever). Then simply use that instead of presenting the two step process -- you can default to the existing server-side determination if the method stored locally fails. I don't mind doing the two-step dance once during first login on a new device, but having to deal with it every time is infuriating and lazy on the part of the company.
- zanedb 9y agoBut what if the user needs to login through a different provider?
- CydeWeys 9y agoThat could easily just be a different link, like the "Forgot password" link, presented at the main login page. You wouldn't interact with it normally, and thus it'd never interrupt your typical logon flow, but it'd be there when you need it. I'm still not really sure what purpose this two-step login is solving, though, as typically every time I use an SSO it's by clicking on a button like "Log in through Facebook" or "Log in through Google", before I'm ever even asked to enter a username. Why do they need to know the username? They'll know that when I log in using the SSO provider.
- daigoba66 9y ago> There might be a better pattern for this, such as making the determination through a xhr request when the username field loses focus. This is what Microsoft does when logging into their various online sites. And it is not better. There’s not much worse than hitting tab and starting to type a password only to get redirected.
- raverbashing 9y agoOr, "if using SSO, leave the password blank" it have separate pages, one for regular users, one for SSO (or pick the provider before asking for user name)
- ghostly_s 9y agoUsers don't know what SSO is. The alternative pattern you see today, "Sign in with X/Y/Z" buttons next to the input fields, is much more usable.