Configure Active Logout
Overview
This page explains how to set the maximum period of user inactivity before automatic logout occurs in the CMS or Console web applications.
User Activity Definition
User activity is defined as any Ajax interaction with the backend. Most user actions in the UI, such as clicking elements or saving data, trigger Ajax requests and reset the inactivity timer.
The following Ajax interactions do not count as user activity:
- The pinger, which retrieves changes from concurrent sessions every 20 seconds.
- The 'live updates' feature in the Realtime tab of the Content audiences application (part of the Relevance module).
Configure the Maximum Inactive Interval
You can configure the maximum inactive interval for each application in minutes by setting the following properties in the Console:
- CMS:
/hippo:configuration/hippo:frontend/cms/cms-static/root/max.inactive.interval.minutes - Console:
/hippo:configuration/hippo:frontend/console/console/root/max.inactive.interval.minutes
By default, the maximum inactive interval is 30 minutes. When a user exceeds this period without activity, the application logs them out automatically.
Disable Active Logout
To disable automatic logout, set the property value to 0. With this configuration, users remain logged in as long as the browser window for the application stays open and active.
Developer Notes
Active logout is always disabled when the application runs in Wicket development mode.
To verify whether active logout is enabled, set the log level for org.hippoecm.frontend.plugins.cms.logout.ActiveLogoutPlugin to INFO. This will log relevant information about the active logout configuration.