Align session codec max-age with the 7-day cap (closes #108)
All checks were successful
check / check (push) Superseded by a newer commit; never tested

This commit was merged in pull request #132.
This commit is contained in:
2026-08-14 06:17:43 +02:00
parent d8f9d149b5
commit 5f18bc3eae
6 changed files with 247 additions and 39 deletions

View File

@@ -168,9 +168,10 @@ one runs out first:
- **Idle expiry** (`SESSION_IDLE_TIMEOUT`, default `24h`) is a sliding
window. Every authenticated request pushes it forward, so a session
in continuous use never hits it, while an abandoned one expires a day
after its last use. Set it to `0` to disable idle expiry entirely;
the absolute cap below still applies. A set-but-unparseable value
aborts startup rather than silently falling back to the default.
after its last use. Any non-positive value (`0`, or a negative
duration such as `-1s`) disables idle expiry entirely; the absolute
cap below still applies. A set-but-unparseable value aborts startup
rather than silently falling back to the default.
- **Absolute expiry** is a fixed 7 days from login. Activity does
**not** extend it: after a week, every session ends and the user
authenticates again.
@@ -182,6 +183,11 @@ idle window rather than on every request, which means a session may
expire up to 10% early relative to the user's true last request, but
never late.
Both clocks are anchored by timestamps stored in the session cookie.
Sessions issued before this feature existed carry neither, so they are
treated as expired: upgrading to a build that has it logs every
existing session out once, and those users sign in again.
#### Invalid values abort startup
The defaults above apply **only** to variables that are unset (or set