logoalt Hacker News

extra88today at 1:59 PM1 replyview on HN

There is no pair for the enterprise users signing in with their company's SSO or those using Passkey.

I think what some sites do is have a visually hidden, not required password field that a password manager can fill in. If it's not a password-based auth, the flow goes to the next step but if it is, it reveals the password field which may already be filled in.


Replies

luckyliontoday at 2:14 PM

Aren't you leaking that there's an account with that email that has a non-password auth method if you treat them differently?

show 1 reply