Session Timeout Warning
The session timeout warning shows a countdown shortly before an idle session ends, so people can choose to stay signed in instead of losing what they were doing. It makes a short idle timeout practical: switch it on whenever you shorten Maximum Session Idle Time.
Where to find it
Architect Panel → Configuration:
- Site Settings — Warn Before Session Timeout, Warn This Many Seconds Before Timeout and When the Countdown Reaches Zero, beside Maximum Session Idle Time
Architect Panel → Security:
- Security Check-up — the Idle timeout and Warn before an idle session ends rows, in the Sessions section
The settings
- Warn Before Session Timeout: switches the warning on. Ships off; while it is off, nothing is added to pages and nothing runs.
- Warn This Many Seconds Before Timeout: how long before the session ends the countdown appears. Ships at 120 seconds. If you set it as long as the idle timeout or longer, the platform uses half the idle timeout instead, so the warning is never on screen from the moment a page loads.
- When the Countdown Reaches Zero: Keep the page open (the default) or Return to the sign-in page.
The countdown itself is driven by Maximum Session Idle Time in the same group. See Setting Maximum Session Idle Time.
What people see
When the time comes, a dialog titled Are you still there? says "You've been inactive for a while, so we're about to sign you out to keep your account secure." under a minutes-and-seconds countdown, with two buttons:
- Stay signed in: tells the server the person is still there and restarts the idle period.
- Log out now: signs out straight away, which is the right choice on a shared computer.
If the countdown reaches zero untouched, Keep the page open leaves the page as it is and shows a sign-in dialog over it, so anything half-typed is still there after signing back in. Return to the sign-in page signs the person out and leaves the page, so unsaved work is lost; it suits kiosks and shared machines.
The countdown follows the server
The time left comes from the server, not a guess in the browser. Every response the page receives updates it, and before the dialog appears the page checks with the server without extending the session. So somebody working in another tab is not interrupted by a warning in a tab they left open, and a laptop that has been asleep does not show a countdown for a session that has already ended. The sign-in page never shows the warning.
Switching it on
- Open Site Settings and find Maximum Session Idle Time. Decide the idle timeout first; the warning is only useful when it is reasonably short.
- Switch on Warn Before Session Timeout.
- Set Warn This Many Seconds Before Timeout. Two minutes suits most people; give longer if your users fill in long forms.
- Choose When the Countdown Reaches Zero: keep the page open for offices, return to the sign-in page for shared or public machines.
- Click Save Settings for the group.
- Test it: temporarily set a short idle timeout on a test installation, sign in, leave the page, and check the dialog and both buttons.
What goes wrong
- No warning ever appears. Check the setting is saved, that the person is signed in on an ordinary page, and that the idle timeout is long enough for the warning to fall within it.
- The warning appears almost immediately. The warning time is close to the idle timeout. Shorten the warning or lengthen the timeout.
- People lose work when the countdown ends. When the Countdown Reaches Zero is set to Return to the sign-in page. Switch to Keep the page open unless the machines are shared.
- Somebody is never signed out. The warning does not change when a session ends; only the idle timeout does. A page that keeps making requests in the background keeps its session alive.
Worked example
A clinic shortens its idle timeout from fourteen days to fifteen minutes after a Security Check-up. It switches on the warning at 120 seconds and chooses Keep the page open, because clinicians type long notes. A week later reception asks for stricter behaviour on the front-desk PCs. As the setting is installation-wide, the clinic keeps Keep the page open and trains reception staff to use Log out now when they step away.
Recommendations
- Switch the warning on whenever you shorten the idle timeout.
- Keep the page open unless your users share machines.
- Allow longer warnings where people fill in long forms.
- Remember the warning is a convenience, not a control; the idle timeout is the control.