Setting admin session timeout limit
Posted: 23 April 2010 04:18 AM   [ Ignore ]  
Research Assistant
Avatar
RankRankRank
Total Posts:  760
Joined  02-11-2007

Is there somewhere I can specify “the amount of time an admin remains logged-in, as it were, ie the duration of an admin session?”

If not, please move this post to the Feature Requests forums.

// edited for clarity

 Signature 

bybjorn.com: ExpressionEngine Freelancer - Premium ExpressionEngine 2.0 Themes - ExpressionEngine Addons @ AddonBakery - contact me on twitter: twitter.com/bjornbjorn - Zerply profile: zerp.ly/bjornbjorn

Profile
 
 
Posted: 23 April 2010 08:44 AM   [ Ignore ]   [ # 1 ]  
Chancellor's Fellow
Avatar
RankRankRankRankRankRankRankRank
Total Posts:  30388
Joined  04-29-2002

http://eehowto.com/index.php/howto/articles/howto-set-the-time-out-limit-in-ee2.x

Profile
MSG
 
 
Posted: 26 April 2010 07:14 AM   [ Ignore ]   [ # 2 ]  
Research Assistant
Avatar
RankRankRank
Total Posts:  760
Joined  02-11-2007

hmm, the backend says something else (referring to “Time Interval for Lockout”):

Enable Password Lockout?
If enabled, only four invalid login attempts are permitted within the time interval specified below. This is a deterrent to hackers using collision attacks to guess poorly chosen passwords.

http://rookery9.aviary.com.s3.amazonaws.com/3746500/3746642_16c3.png

 Signature 

bybjorn.com: ExpressionEngine Freelancer - Premium ExpressionEngine 2.0 Themes - ExpressionEngine Addons @ AddonBakery - contact me on twitter: twitter.com/bjornbjorn - Zerply profile: zerp.ly/bjornbjorn

Profile
 
 
Posted: 26 April 2010 02:09 PM   [ Ignore ]   [ # 3 ]  
Chancellor's Fellow
Avatar
RankRankRankRankRankRankRankRank
Total Posts:  33338
Joined  05-15-2004

So what exactly are you looking for? Yes, can change the timeout interval. Do you mean the lockout time, or what exactly?

Are you, perhaps, referring to the amount of time an admin remains logged-in, as it were, ie the duration of an admin session?

Profile
MSG
 
 
Posted: 26 April 2010 02:29 PM   [ Ignore ]   [ # 4 ]  
Research Assistant
Avatar
RankRankRank
Total Posts:  760
Joined  02-11-2007

(..) the duration of an admin session?

Bingo!

 Signature 

bybjorn.com: ExpressionEngine Freelancer - Premium ExpressionEngine 2.0 Themes - ExpressionEngine Addons @ AddonBakery - contact me on twitter: twitter.com/bjornbjorn - Zerply profile: zerp.ly/bjornbjorn

Profile
 
 
Posted: 26 April 2010 03:09 PM   [ Ignore ]   [ # 5 ]  
Chancellor's Fellow
Avatar
RankRankRankRankRankRankRankRank
Total Posts:  33338
Joined  05-15-2004

That is not a configurable option at this time. So, as per request, moving to FR.

Profile
MSG
 
 
Posted: 26 April 2010 03:42 PM   [ Ignore ]   [ # 6 ]  
Research Assistant
Avatar
RankRankRank
Total Posts:  760
Joined  02-11-2007

Thanks, I replaced the wording in my original message with yours so that the person reading the FR doesn’t have to go through the whole thread to understand what I’m talking about wink

 Signature 

bybjorn.com: ExpressionEngine Freelancer - Premium ExpressionEngine 2.0 Themes - ExpressionEngine Addons @ AddonBakery - contact me on twitter: twitter.com/bjornbjorn - Zerply profile: zerp.ly/bjornbjorn

Profile
 
 
Posted: 30 June 2010 04:35 AM   [ Ignore ]   [ # 7 ]  
Grad Student
Rank
Total Posts:  35
Joined  06-26-2009

What is the length of admin session time?
Anyone know?
=)

Profile
 
 
Posted: 09 July 2010 10:37 PM   [ Ignore ]   [ # 8 ]  
Research Assistant
Avatar
RankRankRank
Total Posts:  604
Joined  05-15-2004

The default duration of the lock out interval feels more like a bug to me ...

1. It happens too quickly; and,

2. If you’ve worked on some code/content and haven’t updated before the (too quick) lockout you loose your work.

This wasn’t how it worked in 1.x ... why the change ...

 Signature 

When you persevere in something in which you have a natural aptitude, the result is excellence. When you persevere in something that does not come naturally, the result is success.

Profile
 
 
Posted: 10 July 2010 12:50 PM   [ Ignore ]   [ # 9 ]  
Grad Student
Rank
Total Posts:  32
Joined  10-04-2009

It’d be nice to be able to set the timeout based on member groups. This way, Super Admins could be one setting (as the developer would hardly pose a security risk after the site is in operation) and another could be for the client/client’s employees (as they would more than likely be logged in in short bursts and need preventing of someone changing stuff while they are out of the room).

Profile
 
 
Posted: 10 July 2010 01:33 PM   [ Ignore ]   [ # 10 ]  
Lab Technician
Avatar
RankRankRankRank
Total Posts:  1014
Joined  05-25-2007

Adding a +1 vote for the ability to control this. It just doesn’t make sense to be working, and suddenly find that you’re logged out. I believe that you do lose work in that case, unless you are able to do something fiddly with multiple logged in screens as I usually do when this happens.

I also believe the lockout arrangement gets confused if you change IP addresses. I’ve had sudden lockouts around times that a local ISP ‘adjusts’ things, and also on short travel between different wireless access points.

The upshot of both of these issues is that I have to run CPs in cookie-only authentication, to avoid being logged out quite often when least expecting it.

Regards,
Clive

Profile