# Login Modal not shown when login page is accessed directly in a private forum

**URL:** https://meta.discourse.org/t/login-modal-not-shown-when-login-page-is-accessed-directly-in-a-private-forum/105188
**Category:** Feature
**Created:** [28 december 2018 om 13:15 UTC](https://meta.discourse.org/t/login-modal-not-shown-when-login-page-is-accessed-directly-in-a-private-forum/105188 "2018-12-28T13:15:43Z")
**Posts on this page:** 16
**Page:** 1

<div class="post-metadata">

### Author: ![gingerman](https://avatars.discourse-cdn.com/v4/letter/g/47e85d/32.png) [@gingerman](https://meta.discourse.org/u/gingerman)
#### Post date: [28 december 2018 om 13:15 UTC](https://meta.discourse.org/t/login-modal-not-shown-when-login-page-is-accessed-directly-in-a-private-forum/105188/1 "2018-12-28T13:15:43Z")

</div>

We have a discourse setup with the following configuration

- Settings - Login only access

**Looks like a Bug** - When the site is accessed as [https://sitename/login](https://sitename/login), it is not showing the login modal.

**Expected** - When the site is accessed as [https://sitename/login](https://sitename/login), it should show the login modal. This works correctly for [https://sitename/signup](https://sitename/signup) where it shows the signup modal.

---

<div class="post-metadata">

### Author: ![itsbhanusharma](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/itsbhanusharma/32/180717_2.png) [@itsbhanusharma](https://meta.discourse.org/u/itsbhanusharma)
#### Post date: [28 december 2018 om 13:28 UTC](https://meta.discourse.org/t/login-modal-not-shown-when-login-page-is-accessed-directly-in-a-private-forum/105188/2 "2018-12-28T13:28:33Z")

</div>

It has traditionally been that way as far as my memory goes!

For the sites requiring login i.e. private forums, anons are redirected to /login and from there, they have to click the log in button (generally displayed twice) to key in their login details and then they can continue from there.

I’m not sure if that’s a longstanding bug or something but it has been this way for the last 1 year at least.

---

<div class="post-metadata">

### Author: ![jomaxro](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jomaxro/32/126216_2.png) [@jomaxro](https://meta.discourse.org/u/jomaxro)
#### Post date: [28 december 2018 om 17:36 UTC](https://meta.discourse.org/t/login-modal-not-shown-when-login-page-is-accessed-directly-in-a-private-forum/105188/3 "2018-12-28T17:36:39Z")

</div>

This doesn’t sound intentional to me. The behavior of `/login` should be consistent regardless of how `login_required` is set. It should always show the login modal.

---

<div class="post-metadata">

### Author: ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### Post date: [28 december 2018 om 18:06 UTC](https://meta.discourse.org/t/login-modal-not-shown-when-login-page-is-accessed-directly-in-a-private-forum/105188/4 "2018-12-28T18:06:10Z")

</div>

Are you sure that you’re logged out when you access that URL? If you’re logged in, well, you don’t need to log in.

You can also check in an incognito window or whatever your browser calls that.

---

<div class="post-metadata">

### Author: ![jomaxro](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jomaxro/32/126216_2.png) [@jomaxro](https://meta.discourse.org/u/jomaxro)
#### Post date: [28 december 2018 om 18:20 UTC](https://meta.discourse.org/t/login-modal-not-shown-when-login-page-is-accessed-directly-in-a-private-forum/105188/5 "2018-12-28T18:20:40Z")

</div>

> [@pfaffman](#):
>
> Are you sure that you’re logged out when you access that URL?

Yeah, I tested this. Here’s a random login required site: [https://forums.anki.com/login](https://forums.anki.com/login). Loading that in incognito does not make the login modal appear. However, loading [https://meta.discourse.org/login](https://meta.discourse.org/login) in incognito does make the login modal appear.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [28 december 2018 om 19:24 UTC](https://meta.discourse.org/t/login-modal-not-shown-when-login-page-is-accessed-directly-in-a-private-forum/105188/6 "2018-12-28T19:24:31Z")

</div>

So this is a confirmed bug @jomaxro?

---

<div class="post-metadata">

### Author: ![jomaxro](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jomaxro/32/126216_2.png) [@jomaxro](https://meta.discourse.org/u/jomaxro)
#### Post date: [28 december 2018 om 19:25 UTC](https://meta.discourse.org/t/login-modal-not-shown-when-login-page-is-accessed-directly-in-a-private-forum/105188/7 "2018-12-28T19:25:17Z")

</div>

I can’t think of a reason for the inconsistency, so yes, I’d say confirmed bug. But there could be history that I’m not aware of that would account for the difference…

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [31 december 2018 om 00:38 UTC](https://meta.discourse.org/t/login-modal-not-shown-when-login-page-is-accessed-directly-in-a-private-forum/105188/8 "2018-12-31T00:38:33Z")

</div>

@techAPJ can you add this to your list?

---

<div class="post-metadata">

### Author: ![techAPJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/techapj/32/342990_2.png) [@techAPJ](https://meta.discourse.org/u/techAPJ)
#### Post date: [31 december 2018 om 01:52 UTC](https://meta.discourse.org/t/login-modal-not-shown-when-login-page-is-accessed-directly-in-a-private-forum/105188/9 "2018-12-31T01:52:07Z")

</div>

> [@jomaxro](#):
>
> This doesn’t sound intentional to me.

This is intentional as per:

> [@Login Popup doesn't work for private Discourse instance](https://meta.discourse.org/t/login-popup-doesnt-work-for-private-discourse-instance/47610/7):
>
> Because in case of login required forums /login page is their homepage which is there to give anonymous users more information about the community they want access to, and how to get access. In case of public forums since the forum is open, anonymous user directly sees what the community is all about via /latest or /categories page, so /login page doesn’t makes sense and we show login modal instead. Also, in case of login required forums, some Admins want to further customize their /login pa…

Should we create a new site setting to control this behaviour or just make login modal show consistently for normal and “login required” sites alike?

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [31 december 2018 om 01:55 UTC](https://meta.discourse.org/t/login-modal-not-shown-when-login-page-is-accessed-directly-in-a-private-forum/105188/10 "2018-12-31T01:55:24Z")

</div>

Why can’t you simply link to the regular login page? Why do you NEED to pop the modal?

I’m reducing this to a feature request discussion, because I am very unclear here what the “problem” is.

---

<div class="post-metadata">

### Author: ![artursmirnov](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/artursmirnov/32/139447_2.png) [@artursmirnov](https://meta.discourse.org/u/artursmirnov)
#### Post date: [26 april 2019 om 17:38 UTC](https://meta.discourse.org/t/login-modal-not-shown-when-login-page-is-accessed-directly-in-a-private-forum/105188/11 "2019-04-26T17:38:02Z")

</div>

We have similar issue at Travis CI community forum. We have only GitHub authorization enabled, because all our users obviously have Gtihub account. So it just opens a popup whenever user clicks on “Login” button. But when the login page is accessed directly by the link (e.g. [https://travis-ci.community/login](https://travis-ci.community/login)), the popup is blocked by browser as it isn’t triggered by user action. And login looks broken because of that.

The same happens when unauthorized user is directed to the new post page ([http://travis-ci.community/new-topic?title=topic%20title](http://travis-ci.community/new-topic?title=topic%20title)). The forum tries to authorize the user, but popup gets blocked by browser and nothing actually happens.

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [29 april 2019 om 01:31 UTC](https://meta.discourse.org/t/login-modal-not-shown-when-login-page-is-accessed-directly-in-a-private-forum/105188/12 "2019-04-29T01:31:33Z")

</div>

This is an interesting and legit edge case, we should force full screen login for cases like this.

@techAPJ can you take this, we already have all the code for “full screen login” so if we do stuff like `/new-topic` it should force you through that flow and not pop windows up.

---

<div class="post-metadata">

### Author: ![techAPJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/techapj/32/342990_2.png) [@techAPJ](https://meta.discourse.org/u/techAPJ)
#### Post date: [1 mei 2019 om 18:12 UTC](https://meta.discourse.org/t/login-modal-not-shown-when-login-page-is-accessed-directly-in-a-private-forum/105188/14 "2019-05-01T18:12:45Z")

</div>

> [@sam](#):
>
> if we do stuff like `/new-topic` it should force you through that flow and not pop windows up.

Done in:

[https://github.com/discourse/discourse/commit/b5ea50a154bdd75c72754651948305e4876d86b8](https://github.com/discourse/discourse/commit/b5ea50a154bdd75c72754651948305e4876d86b8)

> [@artursmirnov](#):
>
> when the login page is accessed directly by the link (e.g. [https://travis-ci.community/login](https://travis-ci.community/login)), the popup is blocked by browser as it isn’t triggered by user action. And login looks broken because of that.

I’ll try to repro this on my local dev instance and will push a fix.

---

<div class="post-metadata">

### Author: ![lucasbasquerotto](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/lucasbasquerotto/32/133376_2.png) [@lucasbasquerotto](https://meta.discourse.org/u/lucasbasquerotto)
#### Post date: [1 mei 2019 om 22:08 UTC](https://meta.discourse.org/t/login-modal-not-shown-when-login-page-is-accessed-directly-in-a-private-forum/105188/15 "2019-05-01T22:08:14Z")

</div>

I think that happens because the login **needs to be on github** , so it tries to open the oauth window to login with github, but the popup should be opened with a **user action**.

When it tries to open the popup when the user just accessed the link, I think the browser blocks the popup **because the user haven’t clicked in anything yet** (it needs a user interaction, otherwise blocks the popup).

If you try to access the login link ([https://travis-ci.community/login](https://travis-ci.community/login)) the popup is blocked, but if you click the login button at the top of the page, it isn’t blocked.

For the most common login flow, where the user can login with just the email (even if there social login options), like here in [meta](https://meta.discourse.org/login), the popup to another domain for the oauth is not triggered when the user access `/login`, but only after the user clicks in the social login option. The first “popup” that shows **is just a modal** in the same page.

A possible solution is to show in a modal, or in a page (if don’t want to be in a modal), that has a button (like `Login with Github`), and only after the user clicks this button the oauth window show (not the best solution, because there is one more step, but I don’t know if this is possible without another step).

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [2 mei 2019 om 02:38 UTC](https://meta.discourse.org/t/login-modal-not-shown-when-login-page-is-accessed-directly-in-a-private-forum/105188/16 "2019-05-02T02:38:39Z")

</div>

Yeah we got to review our auth code and make sure we always check that a “click” happened prior to doing any pop up logging in.

I think just defaulting to “full screen log in” if there was no click should be fine as a general solution. (eg we could simply default to full screen, and then on the “github/google” etc. buttons opt for non full screen)

---

<div class="post-metadata">

### Author: ![techAPJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/techapj/32/342990_2.png) [@techAPJ](https://meta.discourse.org/u/techAPJ)
#### Post date: [9 mei 2019 om 07:36 UTC](https://meta.discourse.org/t/login-modal-not-shown-when-login-page-is-accessed-directly-in-a-private-forum/105188/17 "2019-05-09T07:36:56Z")

</div>

> [@sam](#):
>
> I think just defaulting to “full screen log in” if there was no click should be fine as a general solution. (eg we could simply default to full screen, and then on the “github/google” etc. buttons opt for non full screen)

We now default to full screen login (unless there’s an explicit click) via:

[https://github.com/discourse/discourse/commit/427979e7e51bb9bc858eb6ad2456ce0075fdc643](https://github.com/discourse/discourse/commit/427979e7e51bb9bc858eb6ad2456ce0075fdc643)
