Skip to content

auth: extend session token TTL to 30 days and max lifetime to 1 year - #666

Merged
rgushchin merged 1 commit into
mainfrom
feat/session-token-lifetime
Oct 9, 2026
Merged

rgushchin merged 1 commit into
mainfrom
feat/session-token-lifetime

Conversation

@rgushchin

Copy link
Copy Markdown
Member

Extend interactive web session token TTL from 24 hours to 30 days and increase the hard maximum session lifetime across token refreshes from 30 days to 1 year.

Interactive web session tokens previously expired after 24 hours if
not refreshed by an open browser tab, with a 30-day maximum session
lifetime measured from initial issuance.

Increase the per-token session TTL to 30 days and the absolute
session refresh lifetime cap to 1 year so users remain signed in
across longer periods of browser inactivity.

Signed-off-by: Roman Gushchin <roman.gushchin@linux.dev>
@sashiko-bot

sashiko-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown

Sashiko review

✓ No issues found across 1 commit.

Full review log on sashiko.sashiko.dev

@rgushchin
rgushchin merged commit 0ed51b5 into main Oct 9, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant