Skip to content

SEC-949: token-validity-seconds -1 Not Handled #1193

@spring-projects-issues

Description

@spring-projects-issues

Matthew Reynard(Migrated from SEC-949) said:

When configuring remember-me services and token-validity-seconds is -1 would be nice to have it act like how the browser handles cookies of that age (for the life of the browser). This can be done by putting a expiry time for a few weeks or so on when the cookie is generated, and leaving the maxAge to -1.

Metadata

Metadata

Assignees

No one assigned

    Labels

    in: coreAn issue in spring-security-coretype: enhancementA general enhancementtype: jiraAn issue that was migrated from JIRA

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions