6.0.0-beta6
▾
Tasks
New Task
Search
Photos
Wiki
▾
Tickets
New Ticket
Search
dev.horde.org
Toggle Alerts Log
Help
3/30/26
H
istory
A
ttachments
C
omment
W
atch
Download
Comment on [#12136] Session Timeout not enforced
*
Your Email Address
*
Spam protection
Enter the letters below:
. .. . . __ . . | || | |/ `|\/| |__||___|__|\__.| |
Comment
>> Do Michael's latest commits close this ticket? > > I disagree strongly with the comments. Horde has no reliable session > inactivity timeout mechanism and this needs to be addressed. How can > you argue not to fix a security issue, because its hard to implement?? > > horde currently relies solely on gc_maxlifetime to discard inactive > sessions, which is not reliable! > > see e.g. > http://stackoverflow.com/questions/1236374/session-timeouts-in-php-best-practices
Attachment
Watch this ticket
N
ew Ticket
M
y Tickets
S
earch
Q
uery Builder
R
eports
Saved Queries
Open Bugs
Bugs waiting for Feedback
Open Bugs in Releases
Open Enhancements
Enhancements waiting for Feedback
Bugs with Patches
Enhancements with Patches
Release Showstoppers
Stalled Tickets
New Tickets
Horde 5 Showstoppers