Feat v0.6.9 session lifetime config
- Admin-configurable session TTLs (access: 5m–60m, refresh: 1h–90d) stored in global_settings under "session" key - "Keep me logged in" checkbox on login form; unchecked caps refresh token at 24h, checked uses full admin-configured TTL - generateTokens() reads config instead of hardcoded 15m/7d; expires_in and refresh_expires_in in JSON response reflect actual TTLs - Cookie max-age tracks chosen refresh lifetime (not hardcoded 604800) - Optional idle timeout: admin toggle + configurable duration; server rejects refresh if last_activity_at exceeds threshold - Client SDK activity ping (POST /auth/activity, debounced 1/min) - Admin Settings > Session section with dropdowns for all three knobs - 7 new unit tests for duration parsing, clamping, and defaults Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -444,6 +444,13 @@ func main() {
|
||||
wfScanner.Start()
|
||||
defer wfScanner.Stop()
|
||||
|
||||
// ── Activity ping (authenticated, rate-limited) ──
|
||||
// Client SDK calls this on user interaction (debounced, max 1/min)
|
||||
// to update last_activity_at for idle-timeout tracking.
|
||||
activityGroup := api.Group("/auth")
|
||||
activityGroup.Use(middleware.Auth(cfg, stores.Users, userCache))
|
||||
activityGroup.POST("/activity", authH.Activity)
|
||||
|
||||
// ── Protected routes ────────────────────
|
||||
protected := api.Group("")
|
||||
protected.Use(middleware.Auth(cfg, stores.Users, userCache))
|
||||
|
||||
Reference in New Issue
Block a user