Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Limit sessions to 30 minutes by default #514

Closed
wants to merge 1 commit into from

Conversation

simo5
Copy link
Contributor

@simo5 simo5 commented Feb 27, 2017

When we changed the session handling code we unintentinally extended
sessions expiraion time to the whole ticket lifetime of 24h.

Related to https://fedorahosted.org/freeipa/ticket/5959

Signed-off-by: Simo Sorce simo@redhat.com

When we changed the session handling code we unintentinally extended
sessions expiraion time to the whole ticket lifetime of 24h.

Related to https://fedorahosted.org/freeipa/ticket/5959

Signed-off-by: Simo Sorce <simo@redhat.com>
@tiran
Copy link
Member

tiran commented Feb 27, 2017

Would it makes sense to add https://httpd.apache.org/docs/trunk/mod/mod_session.html#sessionexpiryupdateinterval and set it to a small value like 30 seconds?

The SessionExpiryUpdateInterval directive allows sessions to avoid the cost associated with writing the session each request when only the expiry time has changed. This can be used to make a website more efficient or reduce load on a database when using mod_session_dbd.

@simo5
Copy link
Contributor Author

simo5 commented Feb 27, 2017

No, we do not store sessions in a session db, so that setting is not useful to us.

@tiran tiran added the ack Pull Request approved, can be merged label Feb 27, 2017
@MartinBasti
Copy link
Contributor

master:

  • d5e7a57 Limit sessions to 30 minutes by default

@MartinBasti MartinBasti added the pushed Pull Request has already been pushed label Mar 1, 2017
@MartinBasti MartinBasti closed this Mar 1, 2017
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
ack Pull Request approved, can be merged pushed Pull Request has already been pushed
Projects
None yet
3 participants