Social sign-in gets broader and more secure
· Xenition
Social sign-in just became easier to offer and harder to abuse. Apps can enable it without any registration, and a new brokered lane brings GitHub support. At the same time, the system now requires a verified email from the provider and is opt-in by default. Several other fixes and improvements shipped as well.
Features
- Apps can now offer social sign-in without needing to register anything.
- Added a brokered sign-in lane, including support for GitHub authentication.
- Apps can now use their own OAuth credentials for sign-in again.
Fixes
- Pages for missing resources now correctly return a 404 error instead of showing the homepage.
Improvements
- Social sign-in now requires the provider to have verified the user's email.
- Social sign-in is now disabled by default and can be enabled on request.
- Marketplace listings are now rendered as full pages instead of just snippets.