You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
It's fairly common for login pages to have a "keep me logged in" option. I'd love a way to do this with actix_identity.
Maybe a Identity::login_with_deadline function that would overwrite any visit/login deadline set in IdentityMiddleware? This seems difficult with the current setup, but maybe fields for per-user deadlines could be added to Identity? Then the existing enabled flags could be replaced with Option<Duration> which is either a Copy of the Duration in IdentityMiddleware or a custom one, and that's what gets checked to see if a user should be logged out (not sure if that's even possible).
Probably easier would be to provide methods to access the visit/login_deadline_enabled fields on a given identity, but to achieve the "keep logged in functionality" you'd basically just have to choose between no deadline and a short auto-logout one (ideally we could keep a default deadline even if users choose to be kept logged in).
Would love to hear what others think!
The text was updated successfully, but these errors were encountered:
robjtede
changed the title
[actix_identity] feature: A way to conditionally set visit/login deadlines per login
conditionally set visit/login deadlines per login
Jul 21, 2022
It's fairly common for login pages to have a "keep me logged in" option. I'd love a way to do this with
actix_identity
.Maybe a
Identity::login_with_deadline
function that would overwrite any visit/login deadline set inIdentityMiddleware
? This seems difficult with the current setup, but maybe fields for per-user deadlines could be added toIdentity
? Then the existingenabled
flags could be replaced withOption<Duration>
which is either aCopy
of theDuration
inIdentityMiddleware
or a custom one, and that's what gets checked to see if a user should be logged out (not sure if that's even possible).Probably easier would be to provide methods to access the
visit/login_deadline_enabled
fields on a given identity, but to achieve the "keep logged in functionality" you'd basically just have to choose between no deadline and a short auto-logout one (ideally we could keep a default deadline even if users choose to be kept logged in).Would love to hear what others think!
The text was updated successfully, but these errors were encountered: