Social sign-in gets a rework and a new lane
· Xenition
We shipped a reworked sign-in system today. Most of the changes are around how social sign-in works — what's available by default, what needs setup, and what happens when a provider hasn't verified an email.
Social sign-in
- Apps can now offer social sign-in without needing to register anything — it just works out of the box
- Added a brokered sign-in lane, including support for GitHub authentication
- Apps can use their own OAuth credentials for sign-in again
- Social sign-in now requires the provider to have verified the user's email
- Social sign-in is disabled by default and can be enabled on request
Fixes and refinements
- Pages for missing resources now correctly return a 404 error instead of showing the homepage
- Marketplace listings are now rendered as full pages instead of just meta tags