3 ms·
aws does this every 24 hours for a normal setup and that's pita. They just don't care what their users are doing. Yes I was on middle of something and suddenly
by meow112012 6y ago
aws does this every 24 hours for a normal setup and that's pita. They just don't care what their users are doing. Yes I was on middle of something and suddenly saw that I had to log into their web console again. w???
- CodesInChaos 6y agoFor our service I chose to end sessions at 4 AM local time, but have them last at least 8 hours. This means: * sessions last between 8 and 24+8 hours * if you log in before 20:00, your session ends that night, if you log in after 20:00 it'll last one more day * since this is a B2B application users are unlikely to use the application during session expiry * it's possible to calculate the expiry time during log in and it doesn't require tracking session activity This approach should have similar security properties as a 24h logout, while minimizing the disruption users experience.