Repository navigation
Make the browser session lifetime configurable - #84
Open
ngenov-brml wants to merge 1 commit into
Open
ngenov-brml wants to merge 1 commit into
ngenov-brml wants to merge 1 commit into
Conversation
Browser sessions were fixed at 12 hours. Operators who put the app behind an identity provider with a longer session (Cloudflare Access, AuthKit) had people clicking "Sign in" twice a day for no security gain. Add sessionLifetimeHours to the shared cloud deployment input and ARTIFACT_SERVER_SESSION_LIFETIME_HOURS to the runtime environment. It takes an integer from 1 through 720 and defaults to 12, so existing installations keep their behavior. The Cloudflare, AWS, GCP, Helm and Compose packages pass it through; the session cookie expiry follows it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
User-visible behavior
A browser session lasts 12 hours, fixed in code. An installation behind an identity provider with a longer session, such as Cloudflare Access, still sends people back to "Sign in" twice a day. The provider then lets them straight through, so the short session adds clicks but no security.
Operators can now set the session length:
sessionLifetimeHoursin the shared deployment input.ARTIFACT_SERVER_SESSION_LIFETIME_HOURS(Helm valueconfiguration.sessionLifetimeHours).It takes an integer from 1 through 720 (30 days) and defaults to 12. The session cookie's
Expiresfollows the configured length. Installations that set nothing keep today's behavior.The two bounds live in
src/core/session-lifetime.ts. The deployment contract imports it with a.tspath, so it stays free of application imports.Requirement IDs
No ledger row changes. No requirement states the 12-hour value today. The contract bounds sit in the existing input-rejection table, under DEP-021's checks. Happy to add a row if you want the configurable lifetime as a stated promise.
Tests run
pnpm lint,pnpm typecheck: passpnpm --dir deploy/cloudflare lint,typecheck,vitest run(afterpnpm build): pass, 38 testsscripts/check-conformance-test-ids.rbandvalidate-conformance.rb: passinstallation-identitytest: a 14-day lifetime sets the cookieExpires14 days out, keeps the session at 14 days minus 10 s, and refuses it 5 s after expiry. It fails without the change, because the cookie expires after 12 hours.pnpm test(Vitest): 333 of 334 pass. The failure islifecycle-cli"compact serving withdraws readiness" ("Readiness never entered draining"). It fails the same way on unmodifiedmainon this machine.Not run:
pnpm verify:iteration. It needs Docker, which this machine does not have, so the Pulumi, Helm and Compose integration runs were skipped.Deployment or migration effects
There is no data migration. Sessions already issued keep their stored expiry. The new length applies to sessions created after the deploy.
A deployment JSON that adds
sessionLifetimeHoursneeds this version. Earlier versions reject unknown input keys.Screenshots
No interface change.
🤖 Generated with Claude Code