DNN Forums

Ask questions about your website to get help learning DNN and help resolve issues.

Persistent Cookie & Password Expiration conflict

Sort:
You are not authorized to post a reply.





Growing Member





    I have a bit of a conundrum with using the "Remember Me" checkbox allowing users whos password has expired to keep accessing the website because they don't logout. In looking through the web config at ALL of the different cookies, timeouts, and other property values for these settings, I'm thinking of buying a barrel of Jack Daniels and just ignore this problem.

    If anybody can shed some light on what properties need to be changed I would greatly appreciate it.

    Thank You

     






    Veteran Member





      Hi,

      for remembering passwords, the setting is "PersistentCookieTimeout". It is a value in minutes, a value of 10080 would mean a week for instance (= 60 mins x 24 x 7).

      Find more information here: https://www.dnnsoftware.c...sistentcookietimeout and here: https://www.dnnsoftware.c...-persistent-cookies.

      Happy DNNing!
      Michael

      Michael Tobisch
      DNN★MVP

      dnnWerk Austria
      DNN Connect





      Growing Member





        Thanks Michael !

        Part of my conundrum was at some point in time the value of the "PersistentCookieTimeout" was set very, very high. I am in the process of changing out login procedure and have reduced the timeout to two weeks. Needless to say there are many users that are still able to access the website after their password has expired because their cookie is set so with a long expiration date. I needed a way to determine which users have the cookie value that's longer than the "new" two week value and expire their cookie so that forces them to login at which time they are told that their password has expired. Whew.........I do need that barrel of Jack Daniels.

        Anyway thank for the help, I was able to locate the cookie, determine it's expiration date, and if the expiration is longer than two weeks I expire the cookie and force them to login.

         






        Growing Member





          The other bad thing I found was that the "SlidingExpiration" was set to true so those cookies were NEVER going to expire :-(
          You are not authorized to post a reply.

          These Forums are dedicated to the discussion of DNN Platform.

          For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

          1. If you have (suspected) security issues, please DO NOT post them in the forums but instead follow the official DNN security policy
          2. No Advertising. This includes the promotion of commercial and non-commercial products or services which are not directly related to DNN.
          3. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
          4. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
          5. No Flaming or Trolling.
          6. No Profanity, Racism, or Prejudice.
          7. Site Moderators have the final word on approving / removing a thread or post or comment.
          8. English language posting only, please.

          Would you like to help us?

          Awesome! Simply post in the forums using the link below and we'll get you started.

          Get Involved