Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> The user can login and merrily start building.

I'm surprised that this step was still in there in the new version of the flow. Why not set the user as logged in automatically after registration?



Good question. The manual login ensures that a session is started with the correct authentication credentials. Its a good default way to protect against session hijacking attacks.

I suspect we will automate the first authentication down the road, but with such a small drop-off in the new workflow, we're focusing on more core product features first. There's still lots in the new workflow, website, etc. to improve.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: