mirror of
https://codeberg.org/PostERG/xamxam.git
synced 2026-09-25 01:53:03 +02:00
fix(admin): stop logging out active long-form work; raise idle timeout to 4h
The admin idle timeout (30 min) was refreshed only by navigations and HTMX requests. During long encoding sessions on an open form there are none, so an actively-typing admin was logged out mid-work after ~30-45 min. Add an activity-driven keepalive: - /admin/session-keepalive.php: 204 when authenticated (refreshes admin_last_activity via AdminAuth::isAuthenticated()), 401 otherwise. - admin-session-keepalive.js: marks activity only on real user input (pointer/keyboard/input/scroll/wheel/touch/focus) and pings at most once per 5 min while the tab is visible. A genuinely idle tab never pings, so the idle timeout still applies. Raise the idle window 30 min -> 4 h: for a single-/few-admin back-office whose main workflow is data entry, 30 min still kicked admins who stepped away mid-form. With the keepalive in place, 4 h means "no interaction at all", not "no navigation". Absolute timeout stays 12 h. Also fix session ID rotation, which never fired: it used `$absolute % IDLE_TIMEOUT_SECONDS === 0`, i.e. required a request to land exactly on a multiple of the interval relative to login time. Replaced with an explicit admin_last_rotation timestamp and a ROTATION_INTERVAL_SECONDS (30 min) constant decoupled from the idle timeout, so raising the idle window does not widen the fixation/replay window. Refactor AdminAuth::enforceSessionTimeout() to return bool instead of redirecting/exiting, so the keepalive endpoint can report 401 cleanly rather than letting fetch follow a redirect to the login page. Smoke test (just smoke-session-keepalive) covers activity refresh, 2 h idle accepted, rotation firing, idle rejection+destruction, and unauthenticated rejection. Docs updated.
This commit is contained in:
@@ -99,12 +99,12 @@ ok "Log dir: /var/log/xamxam owned by www-data:xamxam (2775)"
|
||||
|
||||
# PHP-FPM session GC must not reap active admin sessions early.
|
||||
# The app enforces its own server-side idle/absolute timeouts in AdminAuth
|
||||
# (30 min idle / 12 h absolute), so session.gc_maxlifetime needs to be at
|
||||
# (4 h idle / 12 h absolute), so session.gc_maxlifetime needs to be at
|
||||
# least the absolute timeout, and GC re-enabled to clean up stale files.
|
||||
PHP_FPM_INI="/etc/php/8.4/fpm/conf.d/zz-xamxam-session.ini"
|
||||
cat > "$PHP_FPM_INI" <<'INI'
|
||||
; XAMXAM session tuning.
|
||||
; AdminAuth enforces its own idle/absolute timeouts (30 min / 12 h), so
|
||||
; AdminAuth enforces its own idle/absolute timeouts (4 h / 12 h), so
|
||||
; gc_maxlifetime must be >= the absolute timeout or PHP would reap active
|
||||
; sessions from under the app.
|
||||
session.gc_maxlifetime = 43200
|
||||
|
||||
Reference in New Issue
Block a user