Mobile app version of vmapp.org
Login or Join
Moriarity557

: "Remember me": Best practices for expiration and refresh There are many questions with similar titles, but I couldn't find any asking the same thing. Most sites that support user login have a

@Moriarity557

Posted in: #Recommendations #Session #Standards

There are many questions with similar titles, but I couldn't find any asking the same thing.

Most sites that support user login have a "remember me" functionality, where you can check a box and have your session persist through multiple browsing sessions.

Are there any standards or best practices or recommendations in terms of how long the session should last until it expires again? What about for how the expiration time is "refreshed" (e.g. if it expires in one month, should it be updated to one month away on every logged-in page view, or handled some other way)?

10.02% popularity Vote Up Vote Down


Login to follow query

More posts by @Moriarity557

1 Comments

Sorted by latest first Latest Oldest Best

 

@Angie530

I don't think I've ever seen any significant standards around this. General-purpose sites like blogs and forums seem to mostly keep you logged in for about a week, though I suspect that's also due to not bothering to change the default setting in whatever application manages the site.

Beyond that, sites where security is more a cause for concern or money is involved do tend to keep much shorter sessions, or to break them up. Amazon, for example, seems to never log me out at least as far as browsing around and adding things to my cart. But once I try to actually start a purchase or view my account information I do get challenged to identify again.

10% popularity Vote Up Vote Down


Back to top | Use Dark Theme