19 votes

Session Timeout?

Is it just me, or is the session timeout set very short (or strictly tied to an IP)?

I've had to login 3 times this morning at work, and I couldn't have been idle for more than an hour or so each time.

Chrome 66.0.3359 on Android 7.0

19 comments

  1. [4]
    planNine
    Link
    I actually had this happen only in Firefox. When using Firefox, every time I visited the site, I would have to login again. But when using Chromium no such "problem".

    I actually had this happen only in Firefox. When using Firefox, every time I visited the site, I would have to login again. But when using Chromium no such "problem".

    3 votes
    1. [3]
      Silbern
      Link Parent
      I have the opposite problem ironically. Desktop Firefox works fine and remembers my session, whereas Chrome on Android does not and seems to forget my login after maybe ~30 minutes to an hour.

      I have the opposite problem ironically. Desktop Firefox works fine and remembers my session, whereas Chrome on Android does not and seems to forget my login after maybe ~30 minutes to an hour.

      3 votes
      1. [2]
        planNine
        Link Parent
        That's interesting. Maybe you can only be logged-in with a single browser. Was Firefox the first browser you used to login?

        That's interesting. Maybe you can only be logged-in with a single browser.

        Was Firefox the first browser you used to login?

        1 vote
        1. Silbern
          Link Parent
          Yes it was, it was the browser I registered my account on and use the most. However logging in om my android tablet doesn't seem to have any effect on my desktop session; it stays logged in and...

          Yes it was, it was the browser I registered my account on and use the most. However logging in om my android tablet doesn't seem to have any effect on my desktop session; it stays logged in and everything.

          1 vote
  2. [2]
    arghdos
    Link
    FYI: I opened a bug report for you on gitlab
    2 votes
    1. Aerizeon
      Link Parent
      Thanks - I was going to wait until I could give specific reproduction instructions, but I'll update that one when I get home.

      Thanks - I was going to wait until I could give specific reproduction instructions, but I'll update that one when I get home.

      1 vote
  3. [5]
    Fantastitech
    Link
    Looking at dev tools on Chrome and Firefox, my session cookie expiration is set for the time of login. It expires immediately.

    Looking at dev tools on Chrome and Firefox, my session cookie expiration is set for the time of login. It expires immediately.

    2 votes
    1. [4]
      Deimos
      Link Parent
      Odd, is it definitely the time of login and not "time of login, but 2019"? It's supposed to set a one-day expiration if you don't have "keep me logged in" checked, and a one-year one if you do.

      Odd, is it definitely the time of login and not "time of login, but 2019"? It's supposed to set a one-day expiration if you don't have "keep me logged in" checked, and a one-year one if you do.

      2 votes
      1. [3]
        Fantastitech
        Link Parent
        Hmm. I'd like to think I'm above such an rookie mistake but I didn't screenshot it so I can't be sure. I was sure it said 2018. Now it says 2019. Although now I'm not being logged out every few...

        Hmm. I'd like to think I'm above such an rookie mistake but I didn't screenshot it so I can't be sure. I was sure it said 2018. Now it says 2019. Although now I'm not being logged out every few minutes. My session has stayed alive for a couple hours now.

        I'm also quite sure I've been checking the box every login.

        Did you change anything around the time of my comment?

        1 vote
        1. [2]
          Deimos
          Link Parent
          I haven't (deliberately) changed anything related to the sessions today, but have been changing a few other things. I'm not sure, I'll definitely need to look into this more since it seems to be...

          I haven't (deliberately) changed anything related to the sessions today, but have been changing a few other things. I'm not sure, I'll definitely need to look into this more since it seems to be inconsistent for people.

          1 vote
          1. Aerizeon
            Link Parent
            Well something has definitely changed, or else the issue is just that irregular - I too haven't had any more issues today - even my desktop session was still logged in. Unfortunately, I didn't...

            Well something has definitely changed, or else the issue is just that irregular - I too haven't had any more issues today - even my desktop session was still logged in.

            Unfortunately, I didn't really get to look at what was causing it, since I was at work when I created the thread, but hopefully it doesn't pop up again.

            2 votes
  4. [3]
    arghdos
    Link
    Seems to be related to this? (at least, the timing seems to line up).

    Seems to be related to this? (at least, the timing seems to line up).

    1 vote
    1. [2]
      Aerizeon
      Link Parent
      Well, he mentions that he extends logged-in sessions to "much longer", but that doesn't seem to reflect my experience thus far, unless he means ~1h

      Well, he mentions that he extends logged-in sessions to "much longer", but that doesn't seem to reflect my experience thus far, unless he means ~1h

      1 vote
      1. arghdos
        Link Parent
        I was specifically referring to this: I was wondering if (somehow), you weren't being counted as "logged-in" and therefore you got the session timeout after an hour. This does seem to be a bug in...

        I was specifically referring to this:

        I didn't think about the effect on CSRF for registering though, thanks for pointing that out. I'll bump it up to an hour or so. That's still quite low but should get rid of issues like this one.

        I was wondering if (somehow), you weren't being counted as "logged-in" and therefore you got the session timeout after an hour.

        This does seem to be a bug in either case

        1 vote
  5. [4]
    eladnarra
    Link
    I'm getting this issue on Android chrome as well. (I don't have my password manager on my phone, so it's kind of a pain; I can only log back in if I'm near my desktop.)

    I'm getting this issue on Android chrome as well. (I don't have my password manager on my phone, so it's kind of a pain; I can only log back in if I'm near my desktop.)

    1 vote
    1. [3]
      eladnarra
      Link Parent
      I have no idea what's changed, but I stayed logged in for 8 hours while sleeping last night. So it seems intermittent?

      I have no idea what's changed, but I stayed logged in for 8 hours while sleeping last night. So it seems intermittent?

      2 votes
      1. [2]
        eladnarra
        Link Parent
        And now I'm getting it sometimes on my desktop (in Chrome). Weird. Sorry, I know my descriptions aren't particularly detailed or technical, but I figure it helps to know that it's intermittent and...

        And now I'm getting it sometimes on my desktop (in Chrome). Weird.

        Sorry, I know my descriptions aren't particularly detailed or technical, but I figure it helps to know that it's intermittent and on different devices (for me).

        1 vote
  6. EdTinto
    Link
    Same problem. I'm using Firefox Quantum 60.0.1

    Same problem.
    I'm using Firefox Quantum 60.0.1

    1 vote