Every page allauth renders is unstyled: the base templates fill a block nothing uses #63
Labels
No labels
accessibility
authentication
breaking change
bug
documentation
enhancement
interface
internationalisation
observability
security
tier
1
tier
2
tier
3
tier/4
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Blocks
#47 Passkeys, so signing in needs no password at all
Postulo/postulo
Reference
Postulo/postulo#63
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What is wrong
account/base_entrance.htmlis written like this:Every allauth page fills
{% block content %}—login.htmlopens with{% block content %}and closes with{% endblock content %}. A child overriding a blockreplaces it, so the wrapper above is discarded in its entirety and
content_bodyisnever filled by anything.
Counted against the installed allauth: zero of its templates use
content_body, and31 page templates inherit one of Postulo's four overridden bases
(
base_entrance,base_manage,base_manage_email,base_manage_password).What it looks like
The sign-in page, after a wrong password, full width with no card:
text among the other plain black text, with no colour, no icon and no
role;Login:,Password:andRemember Me:— allauth'sdefaults, not Postulo's words;
<button>that reads as a line of text.Settings → Account → Two-Factor Authentication is the same: Postulo's sidebar renders
correctly beside a content column that is unstyled top to bottom, where Activate is
indistinguishable from the sentence above it.
The compiled stylesheet has no rule for
errorlistorhelptext, allauth's defaultclasses, which is consistent with nobody having seen these pages rendered.
Why the tests did not catch it
The axe suite visits
/accounts/login/in both themes and passes, and it passes again onthe failed-attempt page when asked directly: zero violations. Everything axe checks is
correct — the labels are associated, the contrast of black on white is fine, the button is
a button. A page can be entirely unstyled and perfectly accessible to a machine.
It is not accessible to a person:
cue that a submission failed;
make obvious;
by a screen reader and not by eye;
Shape
content_bodytocontentand move Postulo'swrapper out of the way — a
{% block main %}-style wrapper inbase.html, or a bodywrapper the entrance pages extend, so a child overriding
contentstill lands insidethe card.
templates/allauth/elements/—field,button,h1,p,alert— so allauth'spages use the same field partial,
alert-errorandbtn-primaryas everything else.That is what turns
Login:back into the project's own words and makes the error looklike an error.
the design system appears in the rendered body of each allauth page. One class, 31
pages, and it never happens again.
Classification
Bug, and the most visible one found in the audit: it is the first page anybody sees.
Accessibility and interface both. Not breaking.
Depends on
Nothing. #47 adds more allauth pages, so it should not land before this.