Issues with new Login System - Add them here

Issues with new Login System - Add them here

Author
Discussion

RacingPete

Original Poster:

8,883 posts

204 months

Wednesday 13th May 2015
quotequote all
Hi,

As we have rolled out the new login system there are no doubt going to be a few teething issues with it. Across the various posts in here some are coming to light - so I have created this topic so we can keep them in one place and update on how they are getting on and being fixed.

Current issues we are addressing:
  • What's new is auto updating to only show very recent posts and not the full list (seems to be only on new skins) - fix gone out
  • Generation of the homepage is not fully working - fix gone out
  • mobile.pistonheads.com login is not working, or throwing an error
  • Time that your login expires, once logged in, is too short, causing multiple logins. - fix gone out
  • Ad has appeared on new Mobile (Beta2 skin) on the topic pages
  • My Bookmarks/Local Chat etc not working - fix gone out
Any more you spot, then put them in here, and thank you for bearing with us during this massive update to the infrastructure of PistonHeads. :thumbsup:


Edited by RacingPete on Friday 15th May 15:22

RacingPete

Original Poster:

8,883 posts

204 months

Wednesday 13th May 2015
quotequote all
W00DY said:
My classified and forum account haven't merged, probably since they're on different email addresses. I'd like them both to go to my forum email if possible. I currently have no idea how I'd login to my ad here:

http://www.pistonheads.com/classifieds/used-cars/m...

Thanks.
Can you PM me your two email addresses and I will get them matched up under your forum account.

RacingPete

Original Poster:

8,883 posts

204 months

Wednesday 13th May 2015
quotequote all
We are increasing the timeout for your login cookie, and looking into the auto login option.

When logging in, are you choosing "Remember Me"?

RacingPete

Original Poster:

8,883 posts

204 months

Wednesday 13th May 2015
quotequote all
jeremyc said:
'm not given the option. smile

Clicking the 'login' link logs me in without requesting any credentials (nor offering a 'remember me' option). I suspect when I signed in for the first time I would have checked 'remember me'.
OK, got it... still looking into.

RacingPete

Original Poster:

8,883 posts

204 months

Wednesday 13th May 2015
quotequote all
897sma said:
I'm having issues with login, wouldn't accept my details on the main site until I capitalised the letters in my username, I've checked and they're still in lower case on my profile. When I try and log in to the mobile site it just goes round and round in circles - says I've logged in until I try and post then asks me to log in or register.
That is weird, you are in all our systems with lower case username too. Plus the username field is case insensitive so should work for either case.
When you use the mobile site is this on mobile.pistonheads.com - as that is now read only, and login doesn't work.

Edited by RacingPete on Wednesday 13th May 12:35 - edited to correct the word sensitive, tiredness prevails and meant insensitive - is that the nurse calling for my pills?

RacingPete

Original Poster:

8,883 posts

204 months

Wednesday 13th May 2015
quotequote all
We are prioritising the length of time before it auto logs you out at the moment... hopefully have a fix out today.

RacingPete

Original Poster:

8,883 posts

204 months

Wednesday 13th May 2015
quotequote all
schmunk said:
I've tested with both IE10 and IE8 (work computer) - it's whiter than a UKIP convention.
Just to make sure you see what I see - can you post a screenshot?

RacingPete

Original Poster:

8,883 posts

204 months

Wednesday 13th May 2015
quotequote all
schmunk said:
The mighty hand of Corporate IT is preventing me from uploading an image, but to describe it, rather than seeing alternating white and blue/grey backgrounds to posts, every single post has a white background, plus all the page borders are white, so the black text is just swimming in a sea of white. My own posts still show up light blue.

In addition, all the places which should show white text on a dark blue background, e.g. the title banners, are now black text on a white background (with black box).

It's not my monitor, as I can switch back to Mobile(Beta) or Big Blue and see the correct colouration.

Edit: I've also just tried Blackberry 10 browser with Beta 2. All posts are white, but the grey username bar across the full screen helps demarcate posts.


Edited by schmunk on Wednesday 13th May 13:12
Do you see the same view as the screenshot in the post above yours? As that shows grey and white alternative posts.

RacingPete

Original Poster:

8,883 posts

204 months

Wednesday 13th May 2015
quotequote all
ChemicalChaos said:
I can log in just fine on my computer, but my phone will not log in. I see there is an issue with the mobile site, but I always run the desktop site on my phone anyway as I prefer the zoom ability.
Every time I try to log in on my phone, it returns an "invalid username and password combination" notice
Hmmm... this confuses me - if you are viewing desktop on both, then just login here on your mobile and you should be fine.

http://www.pistonheads.com/user/login

RacingPete

Original Poster:

8,883 posts

204 months

Wednesday 13th May 2015
quotequote all
tomjol said:
This isn't really an issue but there doesn't seem to be a discussion thread...

I'm confused about mobile. Is forum access via mobile.pistonheads.com going away? The alternative seems...compromised.
Yes it is... but we have a bit of work still to do to maintain the SEO benefits that site has and migrate them to www.pistonheads.com. So at the moment it is now read only (as you cannot log into it).

If you move to www.pistonheads.com then you have a choice of skins (under My Preferences) as follows:

Classic - A really old skin from 2003 or so (not supported)
Big Blue - The default skin for viewing when not logged in and new registrations, though gives desktop view on a mobile (will soon be deprecated)
Mobile (beta) - The first version of a responsive site (deprectated)
Beta 2 - The new skin we are working on which will be responsive and thus show nicely depending on your screen width <- this is the replacement for mobile.pistonheads.com and will become the default view for logged in users and new registrations.


RacingPete

Original Poster:

8,883 posts

204 months

Wednesday 13th May 2015
quotequote all
tomjol said:
It seems odd to me that we've gone from a situation where both desktop and mobile viewing is good, to one where there is always compromise. I understand that there is a reason for the change, but I would have thought that maintaining a good user experience would be priority number one.
Though that last point is subjective - I really like the mobile version of Beta2 now I have used it for a while (it took me a bit to get use to), but I do concede that the desktop view hasn't quite hit the same mark as Big Blue - we are working on that over the next few weeks, so happy to hear how we can make it better.

RacingPete

Original Poster:

8,883 posts

204 months

Wednesday 13th May 2015
quotequote all
LongBaz463BHP said:
Yep the same for me, I have just had to log in again to reply to this!!!!!!!!!
Fix going out for this in the next 20 mins

RacingPete

Original Poster:

8,883 posts

204 months

Wednesday 13th May 2015
quotequote all
V8mate said:
Login timeout is one thing, but why on earth would it happen whilst using the site?

What was it under the old format? I'm sure I didn't have to log back in on the same device more than twice a year, let alone multiple times each day.

What security issue, exactly, are you trying to cover by having shorter timeouts at all?
It was a slightly off process flow

We have moved to federated login system, so the forums is authenticating against a central login system (and so does the classifieds). This then enables us in the future to roll out the single login to other systems, apps etc.

As part of this we have two forms of knowing who you are. Authenticate and Authorize

The first one just checks who you are and grabs the details of your account based on your cookie from the federated login,
The second will actually check if you are logged in on federated login and then renew your credentials on the site requesting the login (e.g. the Forums).

So every 60 minutes we expire the cookie on the forums, so this requires a re-authorize to update the cookie.

The post reply page is then using Authenticate, so checks your account details and if it doesnt know you are logged in will show a "need to login or register page" to submit a post (not necessarily the wrong thing).

The issue is that it wouldn't go and renew your cookie (as the authorize does this) and keep you moving down the flow to post. We are just looking at whether changing how this page works will still work with people who are not registered - but seems this is the quick fix while working out the flow better in the long term.

For a techie response....


Non-techie....

The cookie expires after 60 minutes and if you haven't visited a page that requires you to be logged in (My Stuff, Post etc) in that time, then it wont renew that cookie, and after 60 minutes you are seen as logged off by any page that wants to know your details. We are changing the flow


Edit: To add this is not a security change, it is because the data from the centralised login system may become stale (if you change username, verification etc) and this enables it to keep fresh and renew.

Edited by RacingPete on Wednesday 13th May 15:21

RacingPete

Original Poster:

8,883 posts

204 months

Wednesday 13th May 2015
quotequote all
SomeRandomDude said:
This is a fake account.

It wont let me log in as CoolFool. I dont think I have broken any of the rules(?). Please help!

Cheers!
I see no record of that username in any of our systems - can you PM me an email address?

RacingPete

Original Poster:

8,883 posts

204 months

Wednesday 13th May 2015
quotequote all
LordGrover said:
Much better than me smile

Will add a bonus multiplier to your post count payments.

RacingPete

Original Poster:

8,883 posts

204 months

Wednesday 13th May 2015
quotequote all
Dont worry, they wont - I have found you, and for some reason you haven't been migrated - we will look at this and sort out and you will be back.

RacingPete

Original Poster:

8,883 posts

204 months

Wednesday 13th May 2015
quotequote all
SomeRandomDude said:
Thank you! When I could not log in I thought, "Rubbish! Have I done something wrong?". Can you inform me when CoolFool is unlocked? Until then, am I safe to post as SomeRandomDude?
OK... you can logout, and log back in as CoolFool using your old username and password - you are now recreated.

RacingPete

Original Poster:

8,883 posts

204 months

Wednesday 13th May 2015
quotequote all
bhstewie said:
I seem to keep being logged out though that appears to be mentioned in the opening post so I guess that's a known issue?
We have put the first pat of the fix to this live now.

RacingPete

Original Poster:

8,883 posts

204 months

Wednesday 13th May 2015
quotequote all
bhstewie said:
Thanks, and not being able to update my email address?
If you PM me with the new email address I can update it for you.

RacingPete

Original Poster:

8,883 posts

204 months

Wednesday 13th May 2015
quotequote all
bhstewie said:
Oh updating it will keep as I'm sure you have your hands full with other more important stuff, but I thought it may be something you need to know about.

If it's by design for now I'll just wait.
Unfortunately we have had issues with people entering their details into a phishing site pretending to be us - this means the scammers come here and edit the email address and make the car cheap as part of a scam. So for the moment we have editing email address off by design to prevent this type of scam.