Project

General

Profile

Actions

Feature #6597

closed

Configurable session lifetime and timeout

Added by Frank Helk over 13 years ago. Updated almost 12 years ago.

Status:
Closed
Priority:
Normal
Category:
Accounts / authentication
Target version:
Start date:
2010-10-07
Due date:
% Done:

0%

Estimated time:
Resolution:
Fixed

Description

I've observed that even when I let the browser open overnight, the redmine session does never time out even when no action is taken.

I suspect that this is intended ("it's no bug, it's a feature"), but I consider this to be a security risk. Maybe I've missed something in the docs, but I'm not aware of such a setting.

Maybe that could be made configurable ?
If it is already, the default timeout value should be set not to be infinite.


Files

AuthSettings.png (6.19 KB) AuthSettings.png Authentification settings Frank Helk, 2010-10-08 09:32
Actions

Also available in: Atom PDF