To avoid bad usability, I would NOT go with the last option.
On Dec 11, 2013, at 5:27 PM, Stian Thorgersen wrote:
I added a cancel button to the login form. It results in a redirect
to "<redirect_uri>?error=access_denied".
Problem with it is that it doesn't make sense for all applications to have it. This
mainly applies to applications that require a login, for example the admin console.
Question is what do we do for those? Some alternatives:
* Add an optional query param to login that disables it (.../tokens/login?nocancel)
* Add a config option to the app that's set through admin console
* Leave it and make the app show a sensible error message - "You're required to
login blah blah, click here to login"
Thoughts?
_______________________________________________
keycloak-dev mailing list
keycloak-dev(a)lists.jboss.org
https://lists.jboss.org/mailman/listinfo/keycloak-dev
--
Gabriel Cardoso
GateIn Portal | User Experience Designer