We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 14883 ☆ A M B ☆
    • 450 Posts
    Is there a way to define a session expiration time. It seems like by default both manager and web sessions stay active as long as the browser session is active - days or weeks even. It’d be nice to know how to lock that down to 30 or 60 minutes of inactivity.
      • 28215
      • 4,149 Posts
      System Setting: "session_cookie_lifetime"
        shaun mccormick | bigcommerce mgr of software engineering, former modx co-architect | github | splittingred.com
        • 25482
        • 0 Posts
        Hi there,

        It appears that the cookie timeout feature mentioned above will only work when the user selects the "remember me" checkbox when logging in. Otherwise the session will not expire. Is there a particular reason for this behavior? I’m trying to adjust the general timeout for the manager like the op asked, but don’t want to force the useer to use the remember me checkbox.

        Has this got to do with php session timeout settings? I tried adding the system setting ’session_gc_maxlifetime’, but to no avail.

        For reference, this is the login timeout behavior in /core/model/modx/processors/security/login.php:

        if ($rememberme) {
            $_SESSION['modx.' . $loginContext . '.session.cookie.lifetime']= $lifetime;
        } else {
            $_SESSION['modx.' . $loginContext . '.session.cookie.lifetime']= 0;
        }


        Any suggestions?
          • 22303 MODX Staff
          • 10,725 Posts
          Without the rememberme option, the default is when the current browser session is ended. Otherwise, it uses the lifetime provided to set the session cookie expiration time.