Uh oh!
There was an error while loading. Please reload this page.
feat(EphemeralSessions): Introduce lax period - #56215
Conversation
dd84951 to
9d458e6Comparenickvergessen
commented
Nov 5, 2025
Other apps were:
|
nickvergessen
left a comment
There was a problem hiding this comment.
So first minute is good, but longer still runs into problems if it happens during the login flow?
I'm not sure we are overestimating peoples speed with passwords manager and 2FA auth a bit.
Should we bump the limit a bit higher to be "save"?
artonge
commented
Nov 5, 2025
Yes, given that this feature only protects against leaving an open session behind, I think it is safe to bump it to 5 min. |
9d458e6 to
870d87bCompareUh oh!
There was an error while loading. Please reload this page.
337feed to
1fd089cCompareSigned-off-by: Louis Chmn <louis@chmn.me>
1fd089c to
ed4a170CompareUh oh!
There was an error while loading. Please reload this page.
artonge
commented
Nov 6, 2025
/backport to stable32 |
artonge
commented
Nov 6, 2025
/backport to stable31 |
artonge
commented
Nov 6, 2025
/backport to stable30 |
artonge
commented
Nov 6, 2025
/backport to stable29 |
artonge
commented
Nov 6, 2025
/backport to stable28 |
artonge
commented
Nov 6, 2025
/backport to stable27 |
artonge
commented
Nov 6, 2025
/backport to stable26 |
artonge
commented
Nov 6, 2025
/backport to stable25 |
In an attempt to fix the numerous number of issues with ephemeral session, I suggest that we introduce a lax period of 60 seconds during which no request will close the session.
For the record, we had/have the following problematic requests: