{"version":"2.1.290","anchor":"device-sign-in-page-for-enterprise-idp-redesigned","canonical_anchor":"device-sign-in-page-for-enterprise-idp-redesigned","heading":"Device-code sign-in page redesigned and gains a way to deny a request","tier":"notice","area":"Auth","scope":"org","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290\/e\/device-sign-in-page-for-enterprise-idp-redesigned","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290","markdown":"### Device-code sign-in page redesigned and gains a way to deny a request\n\nThe gateway's \/device sign-in page is restyled for accessibility, can now deny a sign-in request, and refuses codes already used or expired\n\n**What**\n\nDevice-code sign-in is the flow where a device shows you a code and you type it into a web page to approve the sign-in. The gateway's `\/device` page for enterprise identity providers changed in several ways:\n\n- Redesigned page: the status badge (\"Connect device\" \/ \"Confirm device\") and the error card were replaced by a plain heading, a refusal paragraph marked `role=alert`, and an input labelled with `aria-labelledby`. These make the page easier to use with screen readers. The page now reads \"Enter the code from your device.\"\n\n- Deny endpoint: alongside `POST \/device` there is now `POST \/device\/deny`, which marks a pending code as denied and shows you a result page.\n\n- Safer completion: finishing a sign-in now writes the result only if the code is still pending (`setIfUnchanged`), so a code that was already used or denied cannot be overwritten. Before, the result was written unconditionally.\n\n- Clear message for stale codes: a code that is no longer pending shows \"This device code has already been used or has expired.\"\n\n**Why**\n\nYou can now reject a sign-in request you did not start rather than just ignoring it. A code that has already been used or denied can no longer be completed a second time.\n\n- Area: Auth\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 3\/5\n- Scope: org\n- Heads-up: no"}