This type of user might get confused about whether they should click the link or check the verification code.
Yeah not sure, I think mails like „click this link or type this code“ are common. It does help if the person gets the email on a different device and still offers the comfort of single click. - but let the site admin decide which options their user will understand
Thank you for sharing your feedback!
I want to add that this does not remove the username form. In the current iteration of the upcoming change, you’ll see that there is a dedicated username step after confirming the email address via code:
Recently, we fixed a bug where usernames like “user1” and “user2” would appear, so please let us know if you’re still seeing that anywhere for new accounts.
That’s good, just let me mention in my case there is an moderator approval step after this “account is ready” might be missleading in that case
I had the impression it happend in my current stable version but I can’t check it since I reverted to the old signup, but I will try it again later with your mentioned improvements.
When I try using this new “enable_local_logins_via_code” it is awkward, in that if I use a password manager, in my case, Roboform, which normally enters both the stored username and password simultaneously and then proceeds directly into the site, Roboform now shows 2 Roboform entries one for, in my case, the username (not email as I login with username) and a second for the password
however, in this case instead of filling both the password and username simultaneously, the code immediately proceeds to this screen instead:
Then I need to manually enter my email address. Will the stable version handle this more elegantly? If I use Roboform at that prompt, it of course inserts the username and I get this error:
One potential option is to tell all users to update any password manager logins to email, not username, but this seems obtrusive not to mention it exhibits the same initial behavior, as it goes to the second screen and requires me to do a second step, EVEN if I have changed Roboform, as a test, from username to email:
Anyway, it is just awkward now. I NEVER even click the link “Email me a one-time login code” it just immediately goes to the 2nd prompt.
Don’t get me wrong, I like the 6-digit code option, as will my members, just I would like it to be more graceful than it currently is with a password manager like Roboform.
I think this is awful. I turned it off. Can you please confirm that it’s won’t become mandatory?
Nobody’s going to be bothered to choose a sensible username, unless they’re quite technically minded.
Not everybody does anyway, but unless the “name” is shown everywhere as well as “username” (e.g. on /admin/users/list/active) this is a change for the worse.
(Thanks for Discourse in general. I don’t want to sound ungrateful!)
Here are two things about logging on using that system.
One is that it might be easier if you could type your username or your email address, as one might be easier to remember than the other.
The other is that on my forum the username can’t be changed. No doubt this is a setting I changed ages ago, but it might be worth noting this as the new system relies a bit on the ability to change the username.
Hi! I discovered this new feature today as well. We run a moderation process on our forum, and suddenly new users started getting random usernames like “happybreeze34”. This is an issue for us, as we’d much rather have users go by their own name rather than a random alias.
While trying to work around this, I found that opting out of the “generate random username” option just reverts to a “user1”, “user2”, etc. pattern instead, which isn’t really better.
I also found the overall flow a bit confusing: users first have to enter a code sent by email to get approved, but then, to actually log in, it’s unclear how they’re supposed to proceed, since they’re prompted for a password they never set. You have to once again send a code (and this is not obvious). Once logged in, they then have to figure out how to change their username on their own. Altogether, it makes for a fairly long and confusing onboarding process, especially on our end, since accounts also require moderator approval before users can even reach that stage.
So, as it currently stands, this flow doesn’t quite fit our needs either ![]()
In this case, your best bet is to enable this setting:
You have a point here, we need to review how this flow works for sites that require a staff member to approve accounts. Will look into that and get back to you.
Thanks for the heads up on this issue!
I pushed a fix for this here:
Could you update and have a look and let me know if you’re still facing this issue?
Thanks for your feedback, it is helpful as we are considering if random username generation should be opt-in or opt-out by default. Note that it will not be mandatory at all and you can opt-out using these instructions in the first post:
Once done, here’s what the screen looks like:
We’ve just pushed an update
that improves the flow for sites that require staff approval. Please give it a try after updating and let us know if you come across any issues!
No, does pretty much the exact same thing. From Roboform, it inserts the email address, pauses a second or two, then goes to the 6-digit prompt with the email visible. So Roboform or something seems to be triggering the “Email me a one-time login code” even though I never clicked it, as opposed to entering the password and proceeding direct to discourse.
I recall a while back one can download a free copy of Roboform and have 10 logins, if you want to exactly test that particular password manager.
https://meta.discourse.org/t/easier-account-signup-using-email-codes/407068/42
Once done, here’s what the screen looks like:
I originally tried it with and without allowing random username generation. It made no difference.
Tonight I changed Username change period from 0 to 1 (i.e. now allowing username changes). It seems to work much better. Two things were different (unless I have not been paying attention):
- The screen above, asking for a username, appeared. Before, IT DID NOT APPEAR. That makes sense in a way – but this effect of the
Username change periodsetting should be mentioned in the instructions. - A screen (not mentioned in this topic) appeared before the username one, asking for Full name and custom fields to be entered. This is good. But this also DID NOT APPEAR before. The difference doesn’t make any sense.
The other change I would want to see before using this new feature relates to the login process (i.e. after the user has logged out and wants back in again).
- The “Email me a one-time login code” option should have the same prominence as the “Log In” button. At the minute it’s not really intuitive. I bet a lot of (non-technical) people would just think they’ve lost their password.
- Maybe keep one button, with a message: “If you do not enter a password we will email you a one-time login code.”
- Maybe “I have lost my password” could somehow include the idea that the same procedure will send a password creation link – “Reset or create password”?
- The ideas in this paragraph of the “Set password” email jump around too much: “Somebody asked to add a password to your account on XYZ. Alternatively, you can log in using any supported online service (Google, Facebook, etc) that is associated with this validated email address.” The second sentence will not apply to many forums anyway.
In its favour, I think one-time codes will work better than login links with the Discourse Hub app, as I think the old login links opened in the browser rather than the Hub app.
Thanks, I will try it!
I have the impression something in the sign-up process doesn’t work if a forum uses the invite code site setting. I am able to enter only the email address, and the forum tells me an email was sent, but I didn’t receive one, and the logs also don’t show that one has been sent.
After I disabled the upcoming change, sign-up worked as expected, sending an email again.
I like the idea of improving user experience and making things more frictionless, but not wild about this the way it’s implemented for my user base (just discovered it today as three people signed up to my community and I started wondering why French-speaking cat ladies had names like FriskyAlligator29 and how/why they had skipped so many of our signup fields.
Explanation: population with overall very low digital and cybersec literacy, probably use their cat name or some variation thereof as their email password, and I’d rather be training them to use strong passwords and 2FA (or at least a password manager with better passwords) than use magic links in email…
Also, we « guard the gates » quite seriously for new user signups with a bunch of questions that allow us to triage people upon entry and start out with important information for how to welcome them (context: sick pets, sometimes emergencies or panicked owners, veterinarians… they don’t follow the same « flow »).
Explanation: population with overall very low digital and cybersec literacy, probably use their cat name or some variation thereof as their email password, and I’d rather be training them to use strong passwords and 2FA (or at least a password manager with better passwords) than use magic links in email…
There are two parts to the changes. One is random username generation, which we are shortly going to switch to default off because you are right, it’s not a great default for all communities.
The second part is using email codes for account validation and logins. This is better than magic links in emails and arguably better than passwords. If not better, simpler. Here’s how the flow goes:
- user signs up, we send a code to their email and show the code input on the page
- user sees code in email, enters in Discourse (can see email on a separate device and continue on same device)
- same for logins
- in both cases, they can have no password at all if they wish, password input is optional
- 2FA can still be applied to the account as a second layer
- other signup requirements (additional user fields, captcha) still apply as well, as configured
I’ve just noticed on a forum which requires signup approval, you submit your email address, type the six-digit code, then see this: “Your account hasn’t been approved yet. You will be notified by email when you are ready to log in.”
This text is a bit topsy turvy since at that point you don’t really feel that you are logging in – you are still registering. Even “Thank you for registering.” as a first sentence would be an improvement.
(Also I hope for sites with custom fields, which might help decide whether to approve a user, that the custom fields get filled in before the text above is displayed.)






