-
Notifications
You must be signed in to change notification settings - Fork 1.1k
Closed
Labels
status: declinedA suggestion or change that we don't feel we should currently applyA suggestion or change that we don't feel we should currently apply
Description
The OWASP Session Management best practices recommend using an absolute session timeout in addition to an idle timeout.
Spring Session currently supports only inactivity timeouts. It would be nice for the library to accommodate absolute timeouts as well.
Metadata
Metadata
Assignees
Labels
status: declinedA suggestion or change that we don't feel we should currently applyA suggestion or change that we don't feel we should currently apply