grouper-users - Re: [grouper-users] Grouper UI default timeout in ITAP container
Subject: Grouper Users - Open Discussion List
List archive
- From: Bill Thompson <>
- To: "Hyzer, Chris" <>
- Cc: " Mailing List" <>
- Subject: Re: [grouper-users] Grouper UI default timeout in ITAP container
- Date: Sat, 8 Jun 2019 10:53:22 -0400
There are three timeouts at play in the Grouper UI with the ITAP container:
- The tomcat java session inactivity timeout (current default config is 30 min)
- The Shib SP timeout inactivity timeout (current default config is 8 hours)
The SSO IdP timeout (configured at each institution, my gut feeling is this is >= 1 hour generally)
- The Shib SP session session lifetime (current default config is 8 hours)
Ive had complaints about 30 min sessions being too short.
In my mind, the current configuration does not make sense. If the tomcat session dies in 30 minutes, the shib SP session will start another one (since active for 8 hours). But whatever the person was working on will be interrupted and a potential CSRF error will occur. I think the tomcat session should equal the shib SP session. If the shib/tomcat is 30 minutes, and the typical SSO/Idp session is >= 60 minutes, then again the user is disrupted of their session, they do not need to login, but might experience an error.
We discussed this on slack, and I recommend we change the *default* shibSP / tomcat timeout to 60 minutes. The 8 hour SP session lifetime should not change. In addition we will document how to overlay adjustments to the config.
Also, btw, Matt Black suggested in jira that we change the UI to show a message about session timeout (so you aren’t surprised the next time you click) which I agree with and we can see if we can get something simple to work before too long.
Let us know any thoughts about this change. 😊
Thanks!
- [grouper-users] Grouper UI default timeout in ITAP container, Hyzer, Chris, 06/07/2019
- Re: [grouper-users] [Ext] Grouper UI default timeout in ITAP container, Bryan Wooten, 06/07/2019
- RE: [grouper-users] [Ext] Grouper UI default timeout in ITAP container, Black, Carey M., 06/08/2019
- RE: [grouper-users] [Ext] Grouper UI default timeout in ITAP container, Hyzer, Chris, 06/08/2019
- RE: [grouper-users] [Ext] Grouper UI default timeout in ITAP container, Redman, Chad, 06/08/2019
- RE: [grouper-users] [Ext] Grouper UI default timeout in ITAP container, Redman, Chad, 06/08/2019
- RE: [grouper-users] [Ext] Grouper UI default timeout in ITAP container, Hyzer, Chris, 06/08/2019
- RE: [grouper-users] [Ext] Grouper UI default timeout in ITAP container, Black, Carey M., 06/08/2019
- Re: [grouper-users] Grouper UI default timeout in ITAP container, Bill Thompson, 06/08/2019
- RE: [grouper-users] Grouper UI default timeout in ITAP container, Hyzer, Chris, 06/09/2019
- Re: [grouper-users] Grouper UI default timeout in ITAP container, Bill Thompson, 06/09/2019
- Re: [grouper-users] Grouper UI default timeout in ITAP container, Hyzer, Chris, 06/10/2019
- Re: [grouper-users] Grouper UI default timeout in ITAP container, Bill Thompson, 06/10/2019
- RE: [grouper-users] Grouper UI default timeout in ITAP container, Hyzer, Chris, 06/10/2019
- Re: [grouper-users] Grouper UI default timeout in ITAP container, Bill Thompson, 06/10/2019
- Re: [grouper-users] Grouper UI default timeout in ITAP container, Hyzer, Chris, 06/10/2019
- Re: [grouper-users] Grouper UI default timeout in ITAP container, Gettes, Michael, 06/10/2019
- Re: [grouper-users] Grouper UI default timeout in ITAP container, Bill Thompson, 06/10/2019
- RE: [grouper-users] Grouper UI default timeout in ITAP container, Hyzer, Chris, 06/10/2019
- Re: [grouper-users] Grouper UI default timeout in ITAP container, Bill Thompson, 06/10/2019
- RE: [grouper-users] Grouper UI default timeout in ITAP container, Hyzer, Chris, 06/10/2019
- Re: [grouper-users] Grouper UI default timeout in ITAP container, Bill Thompson, 06/10/2019
- RE: [grouper-users] Grouper UI default timeout in ITAP container, Hyzer, Chris, 06/10/2019
- Re: [grouper-users] Grouper UI default timeout in ITAP container, Bill Thompson, 06/10/2019
- Re: [grouper-users] Grouper UI default timeout in ITAP container, Bill Thompson, 06/09/2019
- RE: [grouper-users] Grouper UI default timeout in ITAP container, Hyzer, Chris, 06/09/2019
- Re: [grouper-users] [Ext] Grouper UI default timeout in ITAP container, Bryan Wooten, 06/07/2019
Archive powered by MHonArc 2.6.19.