I have in mind such activity: user works in web app more than 
SessionIdleTimeout (calls same services, changes data in database).

Can we imitate “user is already authenticated and tries to login again “ 
sending next request (from some service and using sessionDataKey from last 
successful authentication request)  ?

https://identityserver:9444/passivests?sessionDataKey=bda39656-ed51-4e08-8806-ef12967bed12



From: Farasath Ahamed [mailto:farasa...@wso2.com]
Sent: Thursday, May 11, 2017 11:00 AM
To: Illia Alifanov <illia.alifa...@eleks.com>
Cc: dev@wso2.org
Subject: Re: [Dev] Identity Server 5.1.0 sliding session time expiration

AFAIK, we do extend the current session if the user is already authenticated 
and tries to login again.

What other user activities do you have in mind to based oj which you intend 
extend the session?

On Thursday, May 11, 2017, Illia Alifanov 
<illia.alifa...@eleks.com<mailto:illia.alifa...@eleks.com>> wrote:
Hi.
You understand correctly - session should be extended based on user activity.
Is there any approach in WSO2 Identity Server 5.1 or 5.3?


From: Farasath Ahamed 
[mailto:farasa...@wso2.com<javascript:_e(%7B%7D,'cvml','farasa...@wso2.com');>]
Sent: Wednesday, May 10, 2017 10:48 PM
To: Illia Alifanov 
<illia.alifa...@eleks.com<javascript:_e(%7B%7D,'cvml','illia.alifa...@eleks.com');>>
Cc: dev@wso2.org<javascript:_e(%7B%7D,'cvml','dev@wso2.org');>
Subject: Re: [Dev] Identity Server 5.1.0 sliding session time expiration

Hi Illia,

You can increase the session timeout value using configs in [1].
IIUC what you mean by a sliding session time is that the session should get 
extended based on user activity. Is that correct?


[1] https://docs.wso2.com/display/IS510/Configuring+Session+Timeout

Farasath Ahamed
Software Engineer, WSO2 Inc.; http://wso2.com<http://wso2.com/>
Mobile: +94777603866<tel:%2B94777603866>
Blog: blog.farazath.com<http://blog.farazath.com>
Twitter: @farazath619<https://twitter.com/farazath619>
[Image removed by sender.]<http://wso2.com/signature>



On Wed, May 10, 2017 at 12:55 PM, Illia Alifanov 
<illia.alifa...@eleks.com<javascript:_e(%7B%7D,'cvml','illia.alifa...@eleks.com');>>
 wrote:
Dear, WSO2 dev-team,
Help me please with this question about Identity Server 5.1.0

How we can extend Identity server’s session time. I want to synchronize 
sessions between Identity Server and my web application. My goal - is sliding 
session time depends on user activity. Do you have the best practice solution 
for this case?


Regards,
Illia Alifanov.

________________________________

This e-mail may contain privileged and confidential information. If you are not 
the intended recipient, be aware that any use, disclosure, copying or 
distribution of this e-mail or any attachments is prohibited. If you have 
received this e-mail in error, please notify us immediately by returning it to 
the sender and delete this copy from your system. Thank you.

_______________________________________________
Dev mailing list
Dev@wso2.org<javascript:_e(%7B%7D,'cvml','Dev@wso2.org');>
http://wso2.org/cgi-bin/mailman/listinfo/dev


________________________________

This e-mail may contain privileged and confidential information. If you are not 
the intended recipient, be aware that any use, disclosure, copying or 
distribution of this e-mail or any attachments is prohibited. If you have 
received this e-mail in error, please notify us immediately by returning it to 
the sender and delete this copy from your system. Thank you.


--
Farasath Ahamed
Software Engineer, WSO2 Inc.; http://wso2.com<http://wso2.com/>
Mobile: +94777603866<tel:%2B94777603866>
Blog: blog.farazath.com<http://blog.farazath.com>
Twitter: @farazath619<https://twitter.com/farazath619>
[Image removed by sender.]<http://wso2.com/signature>




________________________________

This e-mail may contain privileged and confidential information. If you are not 
the intended recipient, be aware that any use, disclosure, copying or 
distribution of this e-mail or any attachments is prohibited. If you have 
received this e-mail in error, please notify us immediately by returning it to 
the sender and delete this copy from your system. Thank you.
_______________________________________________
Dev mailing list
Dev@wso2.org
http://wso2.org/cgi-bin/mailman/listinfo/dev

Reply via email to