# SSO isn't the solution to all our login related problems

**URL:** <https://discourse.mozilla.org/t/sso-isnt-the-solution-to-all-our-login-related-problems/4731>\
**Category:** Meta\
**Created:** [October 16, 2015, 10:56pm UTC](https://discourse.mozilla.org/t/sso-isnt-the-solution-to-all-our-login-related-problems/4731 "2015-10-16T22:56:10Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![leo](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/leo/32/35237_2.png) [@leo](https://discourse.mozilla.org/u/leo)\
**Post date:** [October 16, 2015, 10:56pm UTC](https://discourse.mozilla.org/t/sso-isnt-the-solution-to-all-our-login-related-problems/4731/1 "2015-10-16T22:56:11Z")

</div>

Continuing the discussion from [Is Discourse SSO the solution to all our login related problems?](https://discourse.mozilla-community.org/t/is-discourse-sso-the-solution-to-all-our-login-related-problems/1271):

> [@Is Discourse SSO the solution to all our login related problems?](https://discourse.mozilla.org/t/is-discourse-sso-the-solution-to-all-our-login-related-problems/1271/1):
>
> I think so.
> 
> Discourse SSO (Single-Sign-On) allows us to do all authentication and sign-up off of the Discourse site. Now you may ask, why on Earth would we want to do this?
> 
> I see two main reasons: it allows us to reclaim the after\_authenticate hook for [mozillians.org](http://mozillians.org) related purposes and it gives us complete control over users’ usernames.

I no longer think so, at least, not by building our own SSO server. This is because, after a painful few hours of ~~trial and error~~ development, I present: [GitHub - mozilla/discourse-mozillians: Deprecated for: https://github.com/mozilla/discourse-mozilla-iam/](https://github.com/LeoMcA/discourse-mozillians)

This is essentially the mozillians integration which was in `discourse-persona-mozillians` integrated into all authentication systems. This means that we can enable as many auth systems as we want (e.g. Firefox Accounts, Webmaker ID, and Yahoo!) and no matter how a user logs in, they’ll still have their vouched status updated.

This resolves the first reason for using SSO, as for the second reason - giving us complete control over users’ usernames - again I expect we’ll be able to do this through a plugin, or through improving the SSO provider which is built into Discourse (allowing us to use one Discourse instance as an SSO server for all the others).

---

<div class="post-metadata">

**Author:** ![tanner](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/tanner/32/30590_2.png) [@tanner](https://discourse.mozilla.org/u/tanner)\
**Post date:** [October 16, 2015, 11:09pm UTC](https://discourse.mozilla.org/t/sso-isnt-the-solution-to-all-our-login-related-problems/4731/2 "2015-10-16T23:09:01Z")

</div>

> **[Betteridge's law of headlines](https://en.wikipedia.org/wiki/Betteridge&#39;s_law_of_headlines)**
>
> Betteridge's law of headlines is one name for an adage that states: "Any headline that ends in a question mark can be answered by the word no." It is named after Ian Betteridge, a British technology journalist, although the principle is much older. As with similar "laws" (e.g., Murphy's law), it is intended as a humorous adage rather than the literal truth. The maxim has been cited by other names since as early as 1991, when a published compilation of Murphy's Law variants called it "Davis's la...

---

<div class="post-metadata">

**Author:** ![majken](https://sea1.discourse-cdn.com/flex001/user_avatar/discourse.mozilla.org/majken/32/21188_2.png) [@majken](https://discourse.mozilla.org/u/majken)\
**Post date:** [October 17, 2015, 3:30pm UTC](https://discourse.mozilla.org/t/sso-isnt-the-solution-to-all-our-login-related-problems/4731/3 "2015-10-17T15:30:35Z")

</div>

Ooh! That fix is timely, we were just discussing wanting to turn on social  
for the community Discourse, but Yousef pointed out it would break  
Mozillians checking.
