Aman-Mittal opened a new issue, #612:
URL: https://github.com/apache/fineract-backoffice-ui/issues/612

   Two code paths send a signed-out user to `/login` with a `reason` query 
param. The login screen only understands one of them, and the one it ignores is 
the common case.
   
   | Sender | Param it sets | Recognised? |
   |---|---|---|
   | `error.interceptor.ts:143` (401 response) | `reason=session-expired` | yes 
|
   | `idle.service.ts:214` (15-minute idle timeout) | `reason=inactivity` | 
**no** |
   
   `login.component.ts:380` does the comparison:
   
   ```ts
   protected readonly sessionExpired = toSignal(
     this.route.queryParamMap.pipe(map((params) => params.get('reason') === 
SESSION_EXPIRED_REASON)),
     { initialValue: false },
   );
   ```
   
   `SESSION_EXPIRED_REASON` is `'session-expired'` (`error.interceptor.ts:30`). 
`'inactivity'` never matches, so `sessionExpired` stays `false` and the banner 
never renders.
   
   ## Reproduction
   
   `/login?reason=session-expired` — banner shown:
   
   
![session-expired](https://raw.githubusercontent.com/Aman-Mittal/fineract-backoffice-ui/ux-audit-screens-2026-09-21/screens/login-session-expired-banner.jpeg)
   
   > Your session has expired. Please sign in again.
   
   `/login?reason=inactivity` — same screen, nothing:
   
   
![inactivity](https://raw.githubusercontent.com/Aman-Mittal/fineract-backoffice-ui/ux-audit-screens-2026-09-21/screens/login-inactivity-no-banner.jpeg)
   
   I hit this without meaning to: I left a session open, came back, and was 
sitting on the login page with `?reason=inactivity` in the URL and no 
indication of why.
   
   ## Why this is the wrong way round
   
   The idle path is how most users get logged out — it fires on a 15-minute 
timer (`idle.service.ts:62`) during normal work. The 401 path is comparatively 
rare. So the explanation is wired to the uncommon case and missing from the 
common one.
   
   The intent is already documented in the code immediately above the 
comparison:
   
   > True when `errorInterceptor` sent the user back here after a 401, rather 
than the user navigating to sign in. Without this the redirect looks like the 
app dropping them at the login screen for no reason.
   
   That is exactly what the inactivity path does today.
   
   ## Suggested fix
   
   Accept both reasons, and ideally give them separate copy, since "your 
session expired" and "you were signed out after 15 minutes of inactivity" tell 
the user different things about whether to expect it again. A shared constant 
for the two values would stop the pair drifting apart a third time.
   
   Worth noting this is adjacent to #555, which fixed the idle dialog showing 
after the session had already timed out — same subsystem, and the messaging on 
the way out is still incomplete.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to