Uploaded image for project: 'Jira Align'
  1. Jira Align
  2. JIRAALIGN-1637

Session Time Out: Authentication timeout is set to 20 minutes (web.config) which overrides the UI security time out configuration

XMLWordPrintable

    • 9
    • Severity 2 - Major
    • A-Team - VanHalen6
    • No

      Issue Summary

      We have noticed that there is logic in the application that appears to be overriding the security setting for the session time out config settings. Please review the internal code attached along with the splunk logs when reviewing the details of this bug. We also have attached a link to customers' tickets with associated HAR files. 

      Steps to Reproduce

      1. Step 1 - Ensure your session time setting is longer than 20mins (set this to 60mins)
      2. Step 2 - Next navigate to any module 
      3. Step 3 - Let the application go idle for 20 mins then return

      Expected Results

      The system should honor the configuration settings under the platform security tab. 

      Actual Results

      Users are seeing the application log them out within 20mins of being idle 

      Workaround

      No workaround at this time 

              pkreidenkov@atlassian.com Pavlo Kreidenkov (Inactive)
              ddortch@atlassian.com Darryl Dortch (Inactive)
              Votes:
              12 Vote for this issue
              Watchers:
              25 Start watching this issue

                Created:
                Updated:
                Resolved: