1
rickh
Sessions: users must stay logged in
  • 2004/9/15 16:17

  • rickh

  • Just popping in

  • Posts: 94

  • Since: 2004/4/9 6


Hello,

I want that the users of my site stay logged in when they close their browser. Now I found something about sessions in the admin panel and I enabled it. Default the session time is 15 minutes and it works. But after 15 minutes the session ends and users have to log in again. So I changed this to 99999.

Now my question: is it safe to change this 15 minutes to a very large number like 999999 ? So users stay logged in for a long time. Are there any risks when I do this?

grtz

2
rickh
Re: Sessions: users must stay logged in
  • 2004/9/16 14:36

  • rickh

  • Just popping in

  • Posts: 94

  • Since: 2004/4/9 6


someone?

3
metropolis
Re: Sessions: users must stay logged in
  • 2004/9/16 15:12

  • metropolis

  • Not too shy to talk

  • Posts: 159

  • Since: 2004/7/15


Quote:

Now my question: is it safe to change this 15 minutes to a very large number like 999999 ? So users stay logged in for a long time. Are there any risks when I do this?


This is something you have to answer for yourself. Of course there are "risks" when the session timeout is very long. If you have many users there may be a lot of still living sessions. The longer the session lasts the higher the risk that some third person may use this session for evil purposes.

As said - you have to decide how much risk you want to allow.

Login

Who's Online

147 user(s) are online (82 user(s) are browsing Support Forums)


Members: 0


Guests: 147


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: May 31
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits