Issues with new Login System - Add them here

Issues with new Login System - Add them here

Author
Discussion

LongBaz463BHP

2,090 posts

217 months

Wednesday 13th May 2015
quotequote all
Can only log in with me Email address not my user name.
Thanks
Barrie

tomjol

532 posts

117 months

Wednesday 13th May 2015
quotequote all
RacingPete said:
Yes it is... but we have a bit of work still to do to maintain the SEO benefits that site has and migrate them to www.pistonheads.com. So at the moment it is now read only (as you cannot log into it).

If you move to www.pistonheads.com then you have a choice of skins (under My Preferences) as follows:

Classic - A really old skin from 2003 or so (not supported)
Big Blue - The default skin for viewing when not logged in and new registrations, though gives desktop view on a mobile (will soon be deprecated)
Mobile (beta) - The first version of a responsive site (deprectated)
Beta 2 - The new skin we are working on which will be responsive and thus show nicely depending on your screen width <- this is the replacement for mobile.pistonheads.com and will become the default view for logged in users and new registrations.
Thanks for the answer. I've done that, and that's what I think is a compromise smile

Neither of the beta options are anywhere near as pleasant to use in a normal desktop browser as Big Blue but will soon be the only options, and realistically already are the only options unless I don't want to use mobile, which I do.

It seems odd to me that we've gone from a situation where both desktop and mobile viewing is good, to one where there is always compromise. I understand that there is a reason for the change, but I would have thought that maintaining a good user experience would be priority number one.

RacingPete

Original Poster:

8,877 posts

204 months

Wednesday 13th May 2015
quotequote all
tomjol said:
It seems odd to me that we've gone from a situation where both desktop and mobile viewing is good, to one where there is always compromise. I understand that there is a reason for the change, but I would have thought that maintaining a good user experience would be priority number one.
Though that last point is subjective - I really like the mobile version of Beta2 now I have used it for a while (it took me a bit to get use to), but I do concede that the desktop view hasn't quite hit the same mark as Big Blue - we are working on that over the next few weeks, so happy to hear how we can make it better.

rigga

8,730 posts

201 months

Wednesday 13th May 2015
quotequote all
LongBaz463BHP said:
Can only log in with me Email address not my user name.
Thanks
Barrie
Same here for me too, and then I have to do it repeatedly.

LordGrover

33,539 posts

212 months

Wednesday 13th May 2015
quotequote all
RacingPete said:
Though that last point is subjective - I really like the mobile version of Beta2 now I have used it for a while (it took me a bit to get use to), but I do concede that the desktop view hasn't quite hit the same mark as Big Blue - we are working on that over the next few weeks, so happy to hear how we can make it better.
Beta 2 - not nice.


Make it look like this:


Job jobbed.

LongBaz463BHP

2,090 posts

217 months

Wednesday 13th May 2015
quotequote all
rigga said:
Same here for me too, and then I have to do it repeatedly.
Yep the same for me, I have just had to log in again to reply to this!!!!!!!!!

ChemicalChaos

10,393 posts

160 months

Wednesday 13th May 2015
quotequote all
RacingPete said:
Hmmm... this confuses me - if you are viewing desktop on both, then just login here on your mobile and you should be fine.

http://www.pistonheads.com/user/login
Following that link only generates a line of hypertext saying "Message: No HTTP resource that matches the request URI
http://www.pistonheads.com/user/login MessageDetail: No action was found on the controller authentication that matches the request



I have checked the double checked I am on the desktop not mobile version of the login screen on my phone, still getting the "invalid username/password" message

LordGrover

33,539 posts

212 months

Wednesday 13th May 2015
quotequote all
I'm not experiencing related problems, but I get the same with that link using Big Blue on chrome W8.1


andburg

7,289 posts

169 months

Wednesday 13th May 2015
quotequote all
Same issue as reported, when visting im not logged in , clicking login logs me in without seeing logon box.

Unable to see which threads i have read or not

Firefox

tomjol

532 posts

117 months

Wednesday 13th May 2015
quotequote all
RacingPete said:
tomjol said:
It seems odd to me that we've gone from a situation where both desktop and mobile viewing is good, to one where there is always compromise. I understand that there is a reason for the change, but I would have thought that maintaining a good user experience would be priority number one.
Though that last point is subjective - I really like the mobile version of Beta2 now I have used it for a while (it took me a bit to get use to), but I do concede that the desktop view hasn't quite hit the same mark as Big Blue - we are working on that over the next few weeks, so happy to hear how we can make it better.
Poor wording on my part - there isn't always compromise, but there is always a compromise somewhere. I don't have a problem with the mobile skins specifically, it's the fact that using one makes the desktop experience worse than Big Blue which is the issue.

How to make it better? Make it the same wink

RacingPete

Original Poster:

8,877 posts

204 months

Wednesday 13th May 2015
quotequote all
LongBaz463BHP said:
Yep the same for me, I have just had to log in again to reply to this!!!!!!!!!
Fix going out for this in the next 20 mins

V8mate

45,899 posts

189 months

Wednesday 13th May 2015
quotequote all
Login timeout is one thing, but why on earth would it happen whilst using the site?

What was it under the old format? I'm sure I didn't have to log back in on the same device more than twice a year, let alone multiple times each day.

What security issue, exactly, are you trying to cover by having shorter timeouts at all?

Big Rumbly

973 posts

284 months

Wednesday 13th May 2015
quotequote all
RacingPete said:
We are increasing the timeout for your login cookie, and looking into the auto login option.

When logging in, are you choosing "Remember Me"?
Remember me is not highlighted so cant select it

897sma

3,362 posts

144 months

Wednesday 13th May 2015
quotequote all
RacingPete said:
897sma said:
I'm having issues with login, wouldn't accept my details on the main site until I capitalised the letters in my username, I've checked and they're still in lower case on my profile. When I try and log in to the mobile site it just goes round and round in circles - says I've logged in until I try and post then asks me to log in or register.
That is weird, you are in all our systems with lower case username too. Plus the username field is case insensitive so should work for either case.
When you use the mobile site is this on mobile.pistonheads.com - as that is now read only, and login doesn't work.

Edited by RacingPete on Wednesday 13th May 12:35 - edited to correct the word sensitive, tiredness prevails and meant insensitive - is that the nurse calling for my pills?
Just logged out and back in again on the main site and all's well now. It was the mobile.pistonheads on my phone, has it only just changed to read only?

RacingPete

Original Poster:

8,877 posts

204 months

Wednesday 13th May 2015
quotequote all
V8mate said:
Login timeout is one thing, but why on earth would it happen whilst using the site?

What was it under the old format? I'm sure I didn't have to log back in on the same device more than twice a year, let alone multiple times each day.

What security issue, exactly, are you trying to cover by having shorter timeouts at all?
It was a slightly off process flow

We have moved to federated login system, so the forums is authenticating against a central login system (and so does the classifieds). This then enables us in the future to roll out the single login to other systems, apps etc.

As part of this we have two forms of knowing who you are. Authenticate and Authorize

The first one just checks who you are and grabs the details of your account based on your cookie from the federated login,
The second will actually check if you are logged in on federated login and then renew your credentials on the site requesting the login (e.g. the Forums).

So every 60 minutes we expire the cookie on the forums, so this requires a re-authorize to update the cookie.

The post reply page is then using Authenticate, so checks your account details and if it doesnt know you are logged in will show a "need to login or register page" to submit a post (not necessarily the wrong thing).

The issue is that it wouldn't go and renew your cookie (as the authorize does this) and keep you moving down the flow to post. We are just looking at whether changing how this page works will still work with people who are not registered - but seems this is the quick fix while working out the flow better in the long term.

For a techie response....


Non-techie....

The cookie expires after 60 minutes and if you haven't visited a page that requires you to be logged in (My Stuff, Post etc) in that time, then it wont renew that cookie, and after 60 minutes you are seen as logged off by any page that wants to know your details. We are changing the flow


Edit: To add this is not a security change, it is because the data from the centralised login system may become stale (if you change username, verification etc) and this enables it to keep fresh and renew.

Edited by RacingPete on Wednesday 13th May 15:21

SomeRandomDude

6 posts

107 months

Wednesday 13th May 2015
quotequote all
This is a fake account.

It wont let me log in as CoolFool. I dont think I have broken any of the rules(?). Please help!

Cheers!

RacingPete

Original Poster:

8,877 posts

204 months

Wednesday 13th May 2015
quotequote all
SomeRandomDude said:
This is a fake account.

It wont let me log in as CoolFool. I dont think I have broken any of the rules(?). Please help!

Cheers!
I see no record of that username in any of our systems - can you PM me an email address?

LordGrover

33,539 posts

212 months

Wednesday 13th May 2015
quotequote all

SomeRandomDude

6 posts

107 months

Wednesday 13th May 2015
quotequote all
RacingPete said:
SomeRandomDude said:
This is a fake account.

It wont let me log in as CoolFool. I dont think I have broken any of the rules(?). Please help!

Cheers!
I see no record of that username in any of our systems - can you PM me an email address?
As I had to make a fake account, I can not email you until 24 hours have passed.

RacingPete

Original Poster:

8,877 posts

204 months

Wednesday 13th May 2015
quotequote all
LordGrover said:
Much better than me smile

Will add a bonus multiplier to your post count payments.