: "Remember me": Best practices for expiration and refresh There are many questions with similar titles, but I couldn't find any asking the same thing. Most sites that support user login have a
There are many questions with similar titles, but I couldn't find any asking the same thing.
Most sites that support user login have a "remember me" functionality, where you can check a box and have your session persist through multiple browsing sessions.
Are there any standards or best practices or recommendations in terms of how long the session should last until it expires again? What about for how the expiration time is "refreshed" (e.g. if it expires in one month, should it be updated to one month away on every logged-in page view, or handled some other way)?
More posts by @Moriarity557
1 Comments
Sorted by latest first Latest Oldest Best
I don't think I've ever seen any significant standards around this. General-purpose sites like blogs and forums seem to mostly keep you logged in for about a week, though I suspect that's also due to not bothering to change the default setting in whatever application manages the site.
Beyond that, sites where security is more a cause for concern or money is involved do tend to keep much shorter sessions, or to break them up. Amazon, for example, seems to never log me out at least as far as browsing around and adding things to my cart. But once I try to actually start a purchase or view my account information I do get challenged to identify again.
Terms of Use Create Support ticket Your support tickets Stock Market News! © vmapp.org2024 All Rights reserved.