Skip to content
SilktideHelp

Session timeout

Silktide asks you to confirm that visitors are warned how long inactivity can last before they are signed out and lose unsaved work. This applies to pages that appear to be part of a sign-in or authenticated area.

Why this matters

Sessions that expire silently are a common trap in banking, government, healthcare, and account dashboards: someone pauses to find a document, comes back, submits the form, and discovers their session died and their input with it. People with disabilities are hit hardest, because they are the most likely to need those pauses.

Warning people up front - "you will be signed out after 20 minutes of inactivity" - lets them plan, save their work, or keep the session alive. No warning is needed if their data is preserved for more than 20 hours of inactivity.

How to fix it

This check asks you to verify the behaviour manually, because session handling cannot be observed from the page alone:

  1. Establish whether inactivity can sign users out or discard their data. If data survives for more than 20 hours of inactivity, nothing more is needed.
  2. Otherwise, warn users about the timeout duration at the start of the process - for example a note on the sign-in page or above a long form.
  3. Better still, warn just before expiry and offer to extend the session, and preserve entered data across re-authentication (see Time limited data loss).

How Silktide tests this

  1. Examine each page for signs it is part of an authenticated flow: a password field, a form that submits to a sign-in or sign-out address, or a logout link.
  2. Where any of these appear, raise one review prompt for the page, asking you to verify the timeout behaviour yourself.
  3. Pages with none of these signs are skipped. Links to a login page do not trigger the prompt, since nearly every website has one.
  4. Once you have verified a page, record your to mark it as checked.

Troubleshooting

A page was flagged that has nothing to do with signing in

The prompt is triggered by structural hints, and these can occasionally misfire - for example a hidden password field left by a plugin, or a form whose address happens to contain a word like "auth" (as in "author"). If the page genuinely has no session to time out, approve the finding.

Learn more

Last updated

Was this page helpful?

Session timeout | Silktide Help