Hi there,
It appears that the cookie timeout feature mentioned above will only work when the user selects the "remember me" checkbox when logging in. Otherwise the session will not expire. Is there a particular reason for this behavior? I’m trying to adjust the general timeout for the manager like the op asked, but don’t want to force the useer to use the remember me checkbox.
Has this got to do with php session timeout settings? I tried adding the system setting ’session_gc_maxlifetime’, but to no avail.
For reference, this is the login timeout behavior in /core/model/modx/processors/security/login.php:
if ($rememberme) {
$_SESSION['modx.' . $loginContext . '.session.cookie.lifetime']= $lifetime;
} else {
$_SESSION['modx.' . $loginContext . '.session.cookie.lifetime']= 0;
}
Any suggestions?