Issues with new Login System - Add them here
Discussion
Hi,
As we have rolled out the new login system there are no doubt going to be a few teething issues with it. Across the various posts in here some are coming to light - so I have created this topic so we can keep them in one place and update on how they are getting on and being fixed.
Current issues we are addressing:
As we have rolled out the new login system there are no doubt going to be a few teething issues with it. Across the various posts in here some are coming to light - so I have created this topic so we can keep them in one place and update on how they are getting on and being fixed.
Current issues we are addressing:
- What's new is auto updating to only show very recent posts and not the full list (seems to be only on new skins) - fix gone out
- Generation of the homepage is not fully working - fix gone out
- mobile.pistonheads.com login is not working, or throwing an error
- Time that your login expires, once logged in, is too short, causing multiple logins. - fix gone out
- Ad has appeared on new Mobile (Beta2 skin) on the topic pages
- My Bookmarks/Local Chat etc not working - fix gone out
Edited by RacingPete on Friday 15th May 15:22
W00DY said:
My classified and forum account haven't merged, probably since they're on different email addresses. I'd like them both to go to my forum email if possible. I currently have no idea how I'd login to my ad here:
http://www.pistonheads.com/classifieds/used-cars/m...
Thanks.
Can you PM me your two email addresses and I will get them matched up under your forum account.http://www.pistonheads.com/classifieds/used-cars/m...
Thanks.
897sma said:
I'm having issues with login, wouldn't accept my details on the main site until I capitalised the letters in my username, I've checked and they're still in lower case on my profile. When I try and log in to the mobile site it just goes round and round in circles - says I've logged in until I try and post then asks me to log in or register.
That is weird, you are in all our systems with lower case username too. Plus the username field is case insensitive so should work for either case.When you use the mobile site is this on mobile.pistonheads.com - as that is now read only, and login doesn't work.
Edited by RacingPete on Wednesday 13th May 12:35 - edited to correct the word sensitive, tiredness prevails and meant insensitive - is that the nurse calling for my pills?
schmunk said:
The mighty hand of Corporate IT is preventing me from uploading an image, but to describe it, rather than seeing alternating white and blue/grey backgrounds to posts, every single post has a white background, plus all the page borders are white, so the black text is just swimming in a sea of white. My own posts still show up light blue.
In addition, all the places which should show white text on a dark blue background, e.g. the title banners, are now black text on a white background (with black box).
It's not my monitor, as I can switch back to Mobile(Beta) or Big Blue and see the correct colouration.
Edit: I've also just tried Blackberry 10 browser with Beta 2. All posts are white, but the grey username bar across the full screen helps demarcate posts.
Do you see the same view as the screenshot in the post above yours? As that shows grey and white alternative posts.In addition, all the places which should show white text on a dark blue background, e.g. the title banners, are now black text on a white background (with black box).
It's not my monitor, as I can switch back to Mobile(Beta) or Big Blue and see the correct colouration.
Edit: I've also just tried Blackberry 10 browser with Beta 2. All posts are white, but the grey username bar across the full screen helps demarcate posts.
Edited by schmunk on Wednesday 13th May 13:12
ChemicalChaos said:
I can log in just fine on my computer, but my phone will not log in. I see there is an issue with the mobile site, but I always run the desktop site on my phone anyway as I prefer the zoom ability.
Every time I try to log in on my phone, it returns an "invalid username and password combination" notice
Hmmm... this confuses me - if you are viewing desktop on both, then just login here on your mobile and you should be fine.Every time I try to log in on my phone, it returns an "invalid username and password combination" notice
http://www.pistonheads.com/user/login
tomjol said:
This isn't really an issue but there doesn't seem to be a discussion thread...
I'm confused about mobile. Is forum access via mobile.pistonheads.com going away? The alternative seems...compromised.
Yes it is... but we have a bit of work still to do to maintain the SEO benefits that site has and migrate them to www.pistonheads.com. So at the moment it is now read only (as you cannot log into it).I'm confused about mobile. Is forum access via mobile.pistonheads.com going away? The alternative seems...compromised.
If you move to www.pistonheads.com then you have a choice of skins (under My Preferences) as follows:
Classic - A really old skin from 2003 or so (not supported)
Big Blue - The default skin for viewing when not logged in and new registrations, though gives desktop view on a mobile (will soon be deprecated)
Mobile (beta) - The first version of a responsive site (deprectated)
Beta 2 - The new skin we are working on which will be responsive and thus show nicely depending on your screen width <- this is the replacement for mobile.pistonheads.com and will become the default view for logged in users and new registrations.
tomjol said:
It seems odd to me that we've gone from a situation where both desktop and mobile viewing is good, to one where there is always compromise. I understand that there is a reason for the change, but I would have thought that maintaining a good user experience would be priority number one.
Though that last point is subjective - I really like the mobile version of Beta2 now I have used it for a while (it took me a bit to get use to), but I do concede that the desktop view hasn't quite hit the same mark as Big Blue - we are working on that over the next few weeks, so happy to hear how we can make it better.V8mate said:
Login timeout is one thing, but why on earth would it happen whilst using the site?
What was it under the old format? I'm sure I didn't have to log back in on the same device more than twice a year, let alone multiple times each day.
What security issue, exactly, are you trying to cover by having shorter timeouts at all?
It was a slightly off process flowWhat was it under the old format? I'm sure I didn't have to log back in on the same device more than twice a year, let alone multiple times each day.
What security issue, exactly, are you trying to cover by having shorter timeouts at all?
We have moved to federated login system, so the forums is authenticating against a central login system (and so does the classifieds). This then enables us in the future to roll out the single login to other systems, apps etc.
As part of this we have two forms of knowing who you are. Authenticate and Authorize
The first one just checks who you are and grabs the details of your account based on your cookie from the federated login,
The second will actually check if you are logged in on federated login and then renew your credentials on the site requesting the login (e.g. the Forums).
So every 60 minutes we expire the cookie on the forums, so this requires a re-authorize to update the cookie.
The post reply page is then using Authenticate, so checks your account details and if it doesnt know you are logged in will show a "need to login or register page" to submit a post (not necessarily the wrong thing).
The issue is that it wouldn't go and renew your cookie (as the authorize does this) and keep you moving down the flow to post. We are just looking at whether changing how this page works will still work with people who are not registered - but seems this is the quick fix while working out the flow better in the long term.
For a techie response....
Non-techie....
The cookie expires after 60 minutes and if you haven't visited a page that requires you to be logged in (My Stuff, Post etc) in that time, then it wont renew that cookie, and after 60 minutes you are seen as logged off by any page that wants to know your details. We are changing the flow
Edit: To add this is not a security change, it is because the data from the centralised login system may become stale (if you change username, verification etc) and this enables it to keep fresh and renew.
Edited by RacingPete on Wednesday 13th May 15:21
SomeRandomDude said:
Thank you! When I could not log in I thought, "Rubbish! Have I done something wrong?". Can you inform me when CoolFool is unlocked? Until then, am I safe to post as SomeRandomDude?
OK... you can logout, and log back in as CoolFool using your old username and password - you are now recreated.bhstewie said:
Oh updating it will keep as I'm sure you have your hands full with other more important stuff, but I thought it may be something you need to know about.
If it's by design for now I'll just wait.
Unfortunately we have had issues with people entering their details into a phishing site pretending to be us - this means the scammers come here and edit the email address and make the car cheap as part of a scam. So for the moment we have editing email address off by design to prevent this type of scam.If it's by design for now I'll just wait.
Gassing Station | Website Feedback | Top of Page | What's New | My Stuff