[JIRA] (IDP-2124) Allow session cookie to be persistent

peter (Jira) jira at shibboleth.atlassian.net
Wed May 31 19:32:22 UTC 2023


peter ( https://shibboleth.atlassian.net/secure/ViewProfile.jspa?accountId=60ad33f05dc18500704c2ef8 ) *commented* on IDP-2124 ( https://shibboleth.atlassian.net/browse/IDP-2124?atlOrigin=eyJpIjoiNDAyOGU3MDg5YzlhNGYwYjlmNWZjNGM2YTUwNjQ3NGIiLCJwIjoiaiJ9 )

Re: Allow session cookie to be persistent ( https://shibboleth.atlassian.net/browse/IDP-2124?atlOrigin=eyJpIjoiNDAyOGU3MDg5YzlhNGYwYjlmNWZjNGM2YTUwNjQ3NGIiLCJwIjoiaiJ9 )

I’d also prefer if closing the browser wasn’t a noop everywhere from v5 on. Though personally I use private browsing mode a lot (or rather often , as in “open, do specific stuff there, close, repeat”) these days, so this may matter less than in the past.

Also note that the request of course wasn’t about the technicality of some cookies' lifetime (which is why I paraphrased it as “effective SSO lifetime”, possibly still insufficiently precise) but about something/ anything that would allow them to configure SSO to last 2 weeks despite browser restarts.
That may amount to the same thing because AFAIU the session cookie is a necessary but not sufficient condition for SSO to happen (being used as a key to look up storage records) but if I’m still misunderstanding that and there’s a way to achieve their goal using something else entirely (“session policy”) then please advise.

( https://shibboleth.atlassian.net/browse/IDP-2124#add-comment?atlOrigin=eyJpIjoiNDAyOGU3MDg5YzlhNGYwYjlmNWZjNGM2YTUwNjQ3NGIiLCJwIjoiaiJ9 ) Add Comment ( https://shibboleth.atlassian.net/browse/IDP-2124#add-comment?atlOrigin=eyJpIjoiNDAyOGU3MDg5YzlhNGYwYjlmNWZjNGM2YTUwNjQ3NGIiLCJwIjoiaiJ9 )

Get Jira notifications on your phone! Download the Jira Cloud app for Android ( https://play.google.com/store/apps/details?id=com.atlassian.android.jira.core&referrer=utm_source%3DNotificationLink%26utm_medium%3DEmail ) or iOS ( https://itunes.apple.com/app/apple-store/id1006972087?pt=696495&ct=EmailNotificationLink&mt=8 ) This message was sent by Atlassian Jira (v1001.0.0-SNAPSHOT#100225- sha1:a994ca2 )
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/commits/attachments/20230531/e57392b9/attachment-0001.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-avatar-a6a6ee93-fc42-4f10-96dc-91da8ffda523
Type: image/png
Size: 302 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20230531/e57392b9/attachment-0003.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-static-comment-icon-5d23d2a3-72d9-4a28-8bd3-d4cb72f688e3
Type: image/png
Size: 1084 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20230531/e57392b9/attachment-0004.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-static-footer-desktop-logo-26f27f1d-6371-4aaa-b3c1-79a8570b3a55
Type: image/png
Size: 10805 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20230531/e57392b9/attachment-0005.png>


More information about the commits mailing list