feat: Session timeout modal (M2-11002) - #2256
Closed
sricharan-varanasi wants to merge 32 commits into
Closed
Conversation
|
This pull request is automatically being deployed by Amplify Hosting (learn more). |
Contributor
|
Changes pushed to #2251. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
📝 Description
🔗 Jira Ticket M2-11002
Warns the user before an idle logout instead of ending the session with no notice.
Changes include:
REACT_APP_IDLE_WARNING_MIN, capped at half the idle timeout📸 Screenshots
🪤 Peer Testing
Use PR #2257 - it shortens the timings to 3 min idle / 1 min warning so this is observable. On this PR the modal only appears after 25 real minutes.
Sign in, then leave the machine completely alone for 2 minutes.
Expected outcome: the modal appears, counting down from 1:00.
Move the mouse without clicking anything.
Expected outcome: the countdown keeps running. Activity does not dismiss it.
Click Stay logged in.
Expected outcome: the modal closes and you stay signed in past the original 3-minute deadline.
Trigger it again, then click Log out.
Expected outcome: logged out immediately, landing on a plain login page.
Trigger it again and let it run to 0:00.
Expected outcome: logged out with the soft lock - email pre-filled and a banner explaining why.
Open two tabs, let both show the modal, click Stay logged in in one.
Expected outcome: the other tab's modal closes within a second.
✏️ Notes
session-flag-removal(feat: remove enableSessionKeepAlive flag #2255), which sits onsession-sync-local(feat: Share one session across tabs (M2-11052,M2-11002) #2251). Both need to merge first.✅ Checklist
Functionality
Testing
Security & Data Privacy
Logging/Monitoring
Performance
Readability
Change Safety
Backend changes are backwards compatible with old clients, or it is well known they are not and a deployment/rollout plan is in place. This include backend changes being compatible with old mobile app versions, as well as applet versioning within Curious.Destructive database migrations are rolled out in stages. For example, renaming a column means adding a new column and migrating the existing data to that columns in one deployment. Then monitoring to ensure that field isn’t used, and finally removing that old column in a separate deployment.