Ok, this might give me an idea on how to implement something similar within 
the non-Java world. Thanks, much!

On Friday, December 4, 2015 at 9:50:54 AM UTC-6, Christopher Myers wrote:
>
> Not sure about PHP, but on our Java applications, we set a:
>
>   <session-config>
>     <session-timeout>
>       120
>     </session-timeout>
>   </session-config>
>
> value in the web.xml file, which makes the session expire on the 
> application server after, in this case, two hours of inactivity. (Something 
> to be aware of with this is that if you have automated code that pulls from 
> a secured location, like through ajax, then that will keep the session 
> live.)
>
> You could also create functionality within your application to keep track 
> of the session life:
>       MaxInactiveInterval: <%=session.getMaxInactiveInterval()%><br>
>       LastAccessed: <%=new 
> java.util.Date(session.getLastAccessedTime())%><br>
>       Created: <%=new java.util.Date(session.getCreationTime())%><br>
>
> and then terminate it after a threshold (like 120 minutes after the 
> session.getCreationTime() timestamp,) using something like:
>
>   try {
>     Enumeration enames;
>     enames = session.getAttributeNames();
>     while (enames.hasMoreElements()) {
>       try { session.removeAttribute(((String) enames.nextElement())); } 
> catch (Exception e) {}
>     }
>     session.invalidate();
>   } catch (Exception e) {}
>
> Again, this is in Java, but it could give you a direction to dig?
>
>
> Chris
>
>
>
> >>> Sergei Gerasenko <[email protected] <javascript:>> 12/04/15 9:43 AM >>>
> Hi,
>
> I'm just starting with CAS. I've successfully installed it and it's 
> working as described. What I can't quite understand is this:
>
> After I authenticate a user in an app through CAS, I need to create a 
> session within the app. Let's assume php-style session handling though a 
> session cookie. When should I re-validate through CAS again? If the PHP 
> session cookie is set to expire when the browser closes and the user never 
> closes the browser, he will never re-validate with CAS. And I do want the 
> re-validation to happen because let's say the person has been taken out of 
> the group allowed to use the application. On the other hand, I don't want 
> the user to be in the middle of something in the app and a redirect to 
> force him to log into CAS again.
>
> What's the best practice to force re-validation? I'm happy to read about 
> it if somebody has the relevant reference to the docs.
>
>
> Thanks much!
>   Sergei
>
> -- 
> You received this message because you are subscribed to the Google Groups 
> "CAS Community" group.
> To unsubscribe from this group and stop receiving emails from it, send an 
> email to [email protected] <javascript:>.
> Visit this group at http://groups.google.com/a/apereo.org/group/cas-user/.
>

-- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
Visit this group at http://groups.google.com/a/apereo.org/group/cas-user/.

Reply via email to