Accessible login (no exception)
Silktide finds login forms on your pages and asks you to confirm that signing in never requires visitors to remember, transcribe, or puzzle out information. This is the strictest version of the accessible login requirement, allowing no exceptions for image recognition or user-provided content.
Why this matters
Passwords, usernames, and puzzles are all cognitive function tests: they demand memory, transcription, or calculation. For people with cognitive disabilities these tests can make signing in impossible, locking them out of accounts they own. At this level (AAA), even tests that ask users to recognise objects or their own uploaded content are ruled out, because they still exclude people with visual or cognitive impairments.
How to fix it
This check asks you to verify each login form manually. A login form passes if it meets all of the following:
- Password managers work. The form allows software to fill in the
username and password. Use standard fields with
autocomplete="username"andautocomplete="current-password", and never ask for selected characters ("enter the 3rd, 7th, and 1st characters of your PIN"), which defeats them. - Paste is allowed. Do not block pasting into the username or password fields.
- No unassisted puzzle of any kind. A or similar test must not be the only way in - including image-recognition tests and tests based on content the user provided, which the AA version of this check permits.
- No invented username. Requiring a made-up handle (like
@joe1987) is a memory test. An email address or phone number is fine, because people use them everywhere.
If the form cannot be brought in line, offer an alternative sign-in that avoids the cognitive test entirely, such as an emailed sign-in link or a passkey.
If a flagged form already meets these conditions, the finding.
How Silktide tests this
- Examine every form on each page for the shape of a login form: either a username field followed by a password field (with at most a couple of extras such as a "remember me" checkbox), or a single-field first step asking for a username, as some major sites use.
- Flag each detected login form for your review. Whether password managers, paste, and alternatives work can only be confirmed by trying them, so a human decides.
Troubleshooting
A form was flagged that is not a login
The detection looks for the structure of a login form, and occasionally another small form matches it. If the form does not sign anyone in, approve the finding.
How is this different from the AA check?
The AA version allows two exceptions: tests that ask users to recognise common objects, and tests based on content the user provided. This AAA version allows neither.