Add inactivity-based session timeout (closes #66) (#105)
All checks were successful
check / check (push) Successful in 4s
All checks were successful
check / check (push) Successful in 4s
Sessions now carry a server-enforced idle deadline (SESSION_IDLE_TIMEOUT, default 24h) alongside the 7-day absolute cap, refreshed on authenticated activity. Activity never extends the absolute cap.
This commit was merged in pull request #105.
This commit is contained in:
6
TODO.md
6
TODO.md
@@ -26,6 +26,10 @@ capability in the README rationale).
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-08-09 Inactivity-based session timeout: sliding idle expiry
|
||||
(`SESSION_IDLE_TIMEOUT`, default `24h`) refreshed on authenticated
|
||||
requests, with the 7-day absolute cap kept as an independent
|
||||
backstop that activity never extends (#66)
|
||||
- 2026-08-09 Restart recovery and the 60s retry sweep terminally fail an
|
||||
orphaned `retrying` delivery whose target type no longer supports
|
||||
retries, recording a `DeliveryResult` with the reason instead of
|
||||
@@ -89,7 +93,7 @@ capability in the README rationale).
|
||||
- event redelivery endpoint
|
||||
- OpenAPI specification
|
||||
- Analytics dashboard: success rates, response times, volume
|
||||
- Session expiration tuning and a remember-me option
|
||||
- A remember-me option at login
|
||||
- Password change and reset flow
|
||||
- Later, nice to have
|
||||
- email delivery target type
|
||||
|
||||
Reference in New Issue
Block a user