3 ms·
If I'm understanding this right, if a user stays on a single page for longer than 30 seconds, their session is invalidated? That sounds pretty harsh. I typical
by SHOwnsYou 15y ago
If I'm understanding this right, if a user stays on a single page for longer than 30 seconds, their session is invalidated? That sounds pretty harsh.
I typically concatenate the users IP and UserAgent. If the new request doesn't match, the session is invalidated and they need to log in again -- But I also don't have a mobile offering for many of the sites I build, so the changing IPs problem is mitigated substantially.
- espeed 15y agoNo, they can be gone for any length of time. Think of the timestamp stored on the session cookie as a token -- as long as it matches the token on the server it doesn't matter how long the token sits on the user's computer until their next request, it just has to match. The 30-second window is just to reduce false positives from an active user double clicking on a slow/flaky connection. Under the normal case of a matching token, the difference between (stored_session.timestamp - session.timestamp) will equal zero (no difference).