KnowledgeHub
Questions
Tags
Users
Search
Alex Rivera
|
Logout
Edit Question
Title
Body
Our Django application has the following session management requirements. Sessions expire when the user closes the browser. Sessions expire after a period of inactivity. Detect when a session expires due to inactivity and display appropriate message to the user. Warn users of a impending session expiry a few minutes before the end of the inactivity period. Along with the warning, provide users an option to extend their session. If user is working on a long business activity within the app that doesn't involve requests being sent to the server, the session must not timeout. After reading the documentation, Django code and some blog posts related to this, I have come up with the following implementation approach. Requirement 1 This requirement is easily implemented by setting SESSION_EXPIRE_AT_BROWSER_CLOSE to True. Requirement 2 I have seen a few recommendations to use SESSION_COOKIE_AGE to set the session expiry period. But this method has the following problems. The session always expires at the end of the SESSION_COOKIE_AGE even if the user is actively using the application. (This can be prevented by setting the session expiry to SESSION_COOKIE_AGE on every request using a custom middleware or by saving the session on every request by setting SESSION_SAVE_EVERY_REQUEST to true. But the next problem is unavoidable due to the use of SESSION_COOKIE_AGE.) Due to the way cookies work, SESSION_EXPIRE_AT_BROWSER_CLOSE and SESSION_COOKIE_AGE are mutually exclusive i.e. the cookie either expires on browser close or at the specified expiry time. If SESSION_COOKIE_AGE is used and the user closes the browser before the cookie expires, the cookie is retained and reopening the browser will allow the user (or anyone else) into the system without being re-authenticated. Django relies only on the cookie being
Tags (comma-separated)
Save Edits
Cancel