Do I need to auto-login after account activation?
- by Art
This is the standard scenario:
User registers on the site
User receives an account activation email, clicks link to activate
Web site notifies the user that account is activated
Now there are at least two pathways:
User is taken to the login screen and asked to enter login details
User is automatically logged in and taken to a welcome/profile/etc page
While there are obvious benefits in (1) as far as the user's experience is concerned, there could be drawbacks as well. Option (2) offers improved security at cost of UX.
Which of the scenarios is preferable and why? Any serious flaws in any of them?