# Landing page on saml login

**URL:** https://meta.discourse.org/t/landing-page-on-saml-login/149377
**Category:** Support
**Created:** [April 26, 2020, 8:17pm UTC](https://meta.discourse.org/t/landing-page-on-saml-login/149377 "2020-04-26T20:17:02Z")
**Posts on this page:** 15
**Page:** 1

<div class="post-metadata">

### Author: ![sbernhard](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sbernhard/32/208186_2.png) [@sbernhard](https://meta.discourse.org/u/sbernhard)
#### Post date: [April 26, 2020, 8:17pm UTC](https://meta.discourse.org/t/landing-page-on-saml-login/149377/1 "2020-04-26T20:17:02Z")

</div>

On previous versions, a landing page was shown on which the “login” button appeared. Clicking this buttons showed the saml login page.  
Personally, I really liked this behavior. With the current version 2.4.2 this isn’t possible any more as the saml login page is shown immediately.

Is it configurable?

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [April 27, 2020, 1:36am UTC](https://meta.discourse.org/t/landing-page-on-saml-login/149377/2 "2020-04-27T01:36:48Z")

</div>

I am not following, you mean we showed a modal that had a single button “Login with SAML” ?

---

<div class="post-metadata">

### Author: ![sbernhard](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sbernhard/32/208186_2.png) [@sbernhard](https://meta.discourse.org/u/sbernhard)
#### Post date: [April 27, 2020, 6:46am UTC](https://meta.discourse.org/t/landing-page-on-saml-login/149377/3 "2020-04-27T06:46:50Z")

</div>

No.  
In a previous version (I believe it was 2.3.6), it was like this:

 ![login](https://global.discourse-cdn.com/meta/original/3X/c/2/c2679fef1c116bb61b0c5784492f1040dac1121b.png)

After clicking on “Anmelden”, the SAML login window appeared.

If I enable “local logins”, the landing page with the login button appears again, but I do not want to have local login and therefore I need to disable it.

---

<div class="post-metadata">

### Author: ![sbernhard](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sbernhard/32/208186_2.png) [@sbernhard](https://meta.discourse.org/u/sbernhard)
#### Post date: [April 29, 2020, 9:21pm UTC](https://meta.discourse.org/t/landing-page-on-saml-login/149377/4 "2020-04-29T21:21:33Z")

</div>

Can someone help me? maybe @eviltrout ?

---

<div class="post-metadata">

### Author: ![eviltrout](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/eviltrout/32/5275_2.png) [@eviltrout](https://meta.discourse.org/u/eviltrout)
#### Post date: [April 29, 2020, 9:26pm UTC](https://meta.discourse.org/t/landing-page-on-saml-login/149377/5 "2020-04-29T21:26:42Z")

</div>

I certainly didn’t change this on purpose. If you could help us track down when it changed that would be helpful as we could look into the context.

It’s possible it changed for security reasons.

---

<div class="post-metadata">

### Author: ![Falco](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/falco/32/179432_2.png) [@Falco](https://meta.discourse.org/u/Falco)
#### Post date: [April 29, 2020, 9:36pm UTC](https://meta.discourse.org/t/landing-page-on-saml-login/149377/6 "2020-04-29T21:36:33Z")

</div>

This was a long requested improvement to make omniauth behave like real SSO, when the number of omniauth login methods is only one.

> [@SSO vs Oauth2 difference?](https://meta.discourse.org/t/sso-vs-oauth2-difference/76543/20):
>
> This is now implemented: If there is only one external authenticator enabled and local logins are disabled and the site requires login, then users will be directed straight to the external authentication page. This exactly matches the implementation of our Discourse-native SSO. I can’t think of a reason why anyone wouldn’t want this, so this is now the default behaviour. cc @consideRatio @Joralf

---

<div class="post-metadata">

### Author: ![sbernhard](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sbernhard/32/208186_2.png) [@sbernhard](https://meta.discourse.org/u/sbernhard)
#### Post date: [April 29, 2020, 9:36pm UTC](https://meta.discourse.org/t/landing-page-on-saml-login/149377/7 "2020-04-29T21:36:49Z")

</div>

How can I help?

one hint: if you enable “local login”, the “Landing page together with the login button” is shown.

---

<div class="post-metadata">

### Author: ![david](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/david/32/157490_2.png) [@david](https://meta.discourse.org/u/david)
#### Post date: [April 29, 2020, 9:38pm UTC](https://meta.discourse.org/t/landing-page-on-saml-login/149377/8 "2020-04-29T21:38:10Z")

</div>

If you really want the confirmation page, you can link the user to `/login` (rather than the homepage). That will not trigger the login automatically.

But note this is not really supported, it is just a quirk of the implementation and may change at any time.

---

<div class="post-metadata">

### Author: ![Falco](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/falco/32/179432_2.png) [@Falco](https://meta.discourse.org/u/Falco)
#### Post date: [April 29, 2020, 9:39pm UTC](https://meta.discourse.org/t/landing-page-on-saml-login/149377/9 "2020-04-29T21:39:02Z")

</div>

New behavior is better and consistent with SSO login. If a message is needed before login it can be implemented in the Identity Provider.

---

<div class="post-metadata">

### Author: ![sbernhard](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sbernhard/32/208186_2.png) [@sbernhard](https://meta.discourse.org/u/sbernhard)
#### Post date: [April 29, 2020, 9:42pm UTC](https://meta.discourse.org/t/landing-page-on-saml-login/149377/10 "2020-04-29T21:42:00Z")

</div>

ah, good to know.  
I know of 2 reasons:

- show a very nice landing page with some basic information instead of that “boring” login window
- “security” (I know, its not really a big blocker). Cheap hacking scripts on the main URL (without the landing page) would fail hopefully as its required to press the login button first.

Is it possible to configure this behavior?

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [April 30, 2020, 2:29am UTC](https://meta.discourse.org/t/landing-page-on-saml-login/149377/11 "2020-04-30T02:29:00Z")

</div>

> [@sbernhard](#):
>
> Is it possible to configure this behavior?

You are going to need to hire a dev here to build a plugin to change this. As it stands this is the first complaint I have heard about the new system in months.

---

<div class="post-metadata">

### Author: ![sbernhard](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sbernhard/32/208186_2.png) [@sbernhard](https://meta.discourse.org/u/sbernhard)
#### Post date: [April 30, 2020, 6:41am UTC](https://meta.discourse.org/t/landing-page-on-saml-login/149377/12 "2020-04-30T06:41:47Z")

</div>

I’m a dev 🙂 (see my changes in discourse\_saml)

Would you accept a PR which adds a configuration option (default: new behavior)?

---

<div class="post-metadata">

### Author: ![david](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/david/32/157490_2.png) [@david](https://meta.discourse.org/u/david)
#### Post date: [April 30, 2020, 8:48am UTC](https://meta.discourse.org/t/landing-page-on-saml-login/149377/14 "2020-04-30T08:48:39Z")

</div>

> [@sbernhard](#):
>
> “security” (I know, its not really a big blocker). Cheap hacking scripts on the main URL (without the landing page) would fail hopefully as its required to press the login button first.

The automatic redirect should not introduce any security vulnerabilities. If you are aware of an exploit, please let us know via our disclosure program: [discourse/docs/SECURITY.md at main · discourse/discourse · GitHub](https://github.com/discourse/discourse/blob/master/docs/SECURITY.md)

> [@sbernhard](#):
>
> Would you accept a PR which adds a configuration option (default: new behavior)?

I don’t think we want to add more noise to the settings until we have some more users requesting this change.

You could override this in a plugin by patching this method:

> <https://github.com/discourse/discourse/blob/main/app/controllers/application_controller.rb#L697-L714>

So I think you would want to simplify the function right down to

```ruby
def redirect_to_login
  dont_cache_page
  cookies[:destination_url] = destination_url
  redirect_to path("/login")
end

```

---

<div class="post-metadata">

### Author: ![sbernhard](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sbernhard/32/208186_2.png) [@sbernhard](https://meta.discourse.org/u/sbernhard)
#### Post date: [April 30, 2020, 8:56am UTC](https://meta.discourse.org/t/landing-page-on-saml-login/149377/15 "2020-04-30T08:56:43Z")

</div>

Thank you. Very appreciated!  
BTW: You are doing a great job with Discourse.

---

<div class="post-metadata">

### Author: ![system](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/system/32/443519_2.png) [@system](https://meta.discourse.org/u/system)
#### Post date: [May 30, 2020, 8:56am UTC](https://meta.discourse.org/t/landing-page-on-saml-login/149377/16 "2020-05-30T08:56:52Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
