Time limited data loss
Silktide asks you to confirm that when your website signs someone out after a period of inactivity, they can sign back in and continue where they left off without losing anything they entered.
This applies to any authenticated area with a session that expires: account dashboards, application forms, checkout flows, and admin interfaces.
Why this matters
People with disabilities often need longer to complete a form: a user navigates fields one at a time, someone with a motor disability types slowly, and someone with a cognitive disability may pause to gather documents or re-read instructions. If a session quietly expires in the meantime, submitting the form discards everything - and the people most likely to be timed out are the ones for whom re-entering it all is hardest.
Preserving data across re-authentication means a timeout costs the visitor a sign-in, not their work.
How to fix it
This check asks you to verify the behavior manually, because it depends on your session handling:
- Start an activity that takes input, such as a long form, while signed in.
- Let the session expire (or force it to), then sign in again.
- Confirm you return to the same activity with your entered data intact.
If data is lost, common remedies are:
- Save form data on the server or in the browser as the user types, and restore it after re-authentication.
- Present re-authentication in an overlay on top of the current page, so the page state (and its form data) is never discarded.
- Extend or remove the inactivity timeout where security allows.
How Silktide tests this
- Silktide cannot observe session expiry or what happens to entered data afterwards, because that behavior only appears for signed-in users over time.
- Instead, this check raises one review prompt per page, asking you to verify the behavior yourself.
- Once you have verified a page, record your to mark it as checked.