This type of user might get confused about whether they should click the link or check the verification code.
Yeah not sure, I think mails like „click this link or type this code“ are common. It does help if the person gets the email on a different device and still offers the comfort of single click. - but let the site admin decide which options their user will understand
Thank you for sharing your feedback!
I want to add that this does not remove the username form. In the current iteration of the upcoming change, you’ll see that there is a dedicated username step after confirming the email address via code:
Recently, we fixed a bug where usernames like “user1” and “user2” would appear, so please let us know if you’re still seeing that anywhere for new accounts.
That’s good, just let me mention in my case there is an moderator approval step after this “account is ready” might be missleading in that case
I had the impression it happend in my current stable version but I can’t check it since I reverted to the old signup, but I will try it again later with your mentioned improvements.
When I try using this new “enable_local_logins_via_code” it is awkward, in that if I use a password manager, in my case, Roboform, which normally enters both the stored username and password simultaneously and then proceeds directly into the site, Roboform now shows 2 Roboform entries one for, in my case, the username (not email as I login with username) and a second for the password
however, in this case instead of filling both the password and username simultaneously, the code immediately proceeds to this screen instead:
Then I need to manually enter my email address. Will the stable version handle this more elegantly? If I use Roboform at that prompt, it of course inserts the username and I get this error:
One potential option is to tell all users to update any password manager logins to email, not username, but this seems obtrusive not to mention it exhibits the same initial behavior, as it goes to the second screen and requires me to do a second step, EVEN if I have changed Roboform, as a test, from username to email:
Anyway, it is just awkward now. I NEVER even click the link “Email me a one-time login code” it just immediately goes to the 2nd prompt.
Don’t get me wrong, I like the 6-digit code option, as will my members, just I would like it to be more graceful than it currently is with a password manager like Roboform.
I think this is awful. I turned it off. Can you please confirm that it’s won’t become mandatory?
Nobody’s going to be bothered to choose a sensible username, unless they’re quite technically minded.
Not everybody does anyway, but unless the “name” is shown everywhere as well as “username” (e.g. on /admin/users/list/active) this is a change for the worse.
(Thanks for Discourse in general. I don’t want to sound ungrateful!)
Here are two things about logging on using that system.
One is that it might be easier if you could type your username or your email address, as one might be easier to remember than the other.
The other is that on my forum the username can’t be changed. No doubt this is a setting I changed ages ago, but it might be worth noting this as the new system relies a bit on the ability to change the username.
Hi! I discovered this new feature today as well. We run a moderation process on our forum, and suddenly new users started getting random usernames like “happybreeze34”. This is an issue for us, as we’d much rather have users go by their own name rather than a random alias.
While trying to work around this, I found that opting out of the “generate random username” option just reverts to a “user1”, “user2”, etc. pattern instead, which isn’t really better.
I also found the overall flow a bit confusing: users first have to enter a code sent by email to get approved, but then, to actually log in, it’s unclear how they’re supposed to proceed, since they’re prompted for a password they never set. You have to once again send a code (and this is not obvious). Once logged in, they then have to figure out how to change their username on their own. Altogether, it makes for a fairly long and confusing onboarding process, especially on our end, since accounts also require moderator approval before users can even reach that stage.
So, as it currently stands, this flow doesn’t quite fit our needs either ![]()
In this case, your best bet is to enable this setting:
You have a point here, we need to review how this flow works for sites that require a staff member to approve accounts. Will look into that and get back to you.
Thanks for the heads up on this issue!
I pushed a fix for this here:
Could you update and have a look and let me know if you’re still facing this issue?





