Uploaded image for project: 'Red Hat 3scale API Management'
  1. Red Hat 3scale API Management
  2. THREESCALE-11245

[RFE] Implement Idle Session Timeout for Admin Portal users

XMLWordPrintable

    • Icon: Feature Request Feature Request
    • Resolution: Duplicate
    • Icon: Major Major
    • None
    • 2.14.0 GA
    • System
    • False
    • Hide

      None

      Show
      None
    • False
    • Not Started
    • Not Started
    • Not Started
    • Not Started
    • Not Started
    • Not Started

      Customer undertaking penetration testing has observed no apparent Idle Session Timeout for Admin Portal users

      Customer has advised they would like to see the following implemented: 

      •Destroy the session on the server and force the browser to navigate away from any sensitive pages after an appropriate interval of idle time 15 to 20 Minutes. * Set session timeout to the minimal value possible depending on the context of the

      application. * Avoid "infinite" session timeout.

      • Prefer declarative definition of the session timeout to apply a global timeout for all

      application sessions. * Trace session creation/destruction in order to analyze the creation trend and try to

      detect a normal number of session creations (application profiling phase in a attack).|

       

              Unassigned Unassigned
              rhn-support-ahobson Aimi Hobson
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: