What
Device-code sign-in is the flow where a device shows you a code and you type it into a web page to approve the sign-in. The gateway's /device page for enterprise identity providers changed in several ways:
- Redesigned page: the status badge ("Connect device" / "Confirm device") and the error card were replaced by a plain heading, a refusal paragraph marked
role=alert, and an input labelled witharia-labelledby. These make the page easier to use with screen readers. The page now reads "Enter the code from your device." - Deny endpoint: alongside
POST /devicethere is nowPOST /device/deny, which marks a pending code as denied and shows you a result page. - Safer completion: finishing a sign-in now writes the result only if the code is still pending (
setIfUnchanged), so a code that was already used or denied cannot be overwritten. Before, the result was written unconditionally. - Clear message for stale codes: a code that is no longer pending shows "This device code has already been used or has expired."
Why
You can now reject a sign-in request you did not start rather than just ignoring it. A code that has already been used or denied can no longer be completed a second time.