[Tickets #12136] Re: Session Timeout not enforced

noreply at bugs.horde.org noreply at bugs.horde.org
Fri May 3 10:16:46 UTC 2013


DO NOT REPLY TO THIS MESSAGE. THIS EMAIL ADDRESS IS NOT MONITORED.

Ticket URL: http://bugs.horde.org/ticket/12136
------------------------------------------------------------------------------
  Ticket             | 12136
  Updated By         | peter.meier+horde at immerda.ch
  Summary            | Session Timeout not enforced
  Queue              | Horde Framework Packages
  Version            | Git master
  Type               | Bug
  State              | Feedback
  Priority           | 2. Medium
  Milestone          |
  Patch              |
  Owners             |
------------------------------------------------------------------------------


peter.meier+horde at immerda.ch (2013-05-03 10:16) wrote:

Thanks for your extensive answer. I learned a lot.

So the only question that remains is that now cookie-lifetime is equal  
to session-timeout due to

https://github.com/horde/horde/commit/722b1912b37d2ece4d991193d157cf7179cbee0c

So this means that if I want the user to be logged out after she  
closes her browser, I need to set it to 0 and to have a user logged  
out *some* time (x seconds after she closed her tab) I need to  
configure the x seconds in the gc_maxlifetime. Right? This is not that  
obvious from how things are currently explained, but I think I got now  
the picture.






More information about the bugs mailing list