[ https://issues.apache.org/jira/browse/KNOX-3005?focusedWorklogId=903416&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-903416 ]
ASF GitHub Bot logged work on KNOX-3005: ---------------------------------------- Author: ASF GitHub Bot Created on: 02/Feb/24 19:34 Start Date: 02/Feb/24 19:34 Worklog Time Spent: 10m Work Description: smolnar82 commented on code in PR #839: URL: https://github.com/apache/knox/pull/839#discussion_r1476594324 ########## gateway-provider-security-jwt/src/main/java/org/apache/knox/gateway/provider/federation/jwt/filter/AbstractJWTFilter.java: ########## @@ -381,11 +390,29 @@ protected boolean validateToken(final HttpServletRequest request, final HttpServ return false; } - private boolean isTokenEnabled(String tokenId) throws UnknownTokenException { - final TokenMetadata tokenMetadata = tokenStateService == null ? null : tokenStateService.getTokenMetadata(tokenId); + private boolean isTokenEnabled(TokenMetadata tokenMetadata) throws UnknownTokenException { return tokenMetadata == null ? true : tokenMetadata.isEnabled(); } + private boolean isNotIdle(TokenMetadata tokenMetadata) throws UnknownTokenException { Review Comment: @pzampino - Did you check if the new PS satisfies what you asked here? Issue Time Tracking ------------------- Worklog Id: (was: 903416) Time Spent: 2h 20m (was: 2h 10m) > Implement Knox idle session time > -------------------------------- > > Key: KNOX-3005 > URL: https://issues.apache.org/jira/browse/KNOX-3005 > Project: Apache Knox > Issue Type: New Feature > Components: KnoxSSO > Affects Versions: 2.1.0 > Reporter: Sandor Molnar > Assignee: Sandor Molnar > Priority: Critical > Fix For: 2.1.0 > > Time Spent: 2h 20m > Remaining Estimate: 0h > > With the recent work of KNOX-2961, the new SSO token invalidation > functionality, Knox could provide idle session timeout behavior for UIs. > It will likely not include the usual UI pop-up approach (like when the > end-user is informed about being idle too long), but it would effectively > terminate idle SSO sessions and force an explicit login. > It's also worth mentioning the idleness measurement solely depends on backend > activities through the KnoxSSO Cookie federation filter. and will not take > any client-side action (such as scrolling on the page, client-side > pagination, etc..) into account. -- This message was sent by Atlassian Jira (v8.20.10#820010)