WebUI session timeout

telenoar

Cadet
Joined
Nov 23, 2020
Messages
2
Hi, I'm on FreeNAS 11.1.

Yesterday I ran some admin work in the web GUI, closed the tab... and 16 hours later discovered that I didn't need to re-authenticate.
How can I change that, so the session would expire after X time or tab-closure?

Didn't find a setting for it in the UI.
I dug around... searching brought up one old answer about a "session.php" file that I couldn't locate. And I found a "SESSION_EXPIRE_AT_BROWSER_CLOSE" setting in /usr/local/lib/python3.6/site-packages/django/conf, but I don't call myself a linux expert and not familiar with django, so I may be looking in the totally wrong place.

Thanks
 

JV9

Dabbler
Joined
Aug 19, 2021
Messages
25
TrueNAS Core - TrueNAS-12.0-U5

I have the same question, but the opposite problem: the default timeout is WAY too short when you're setting up the system and bouncing between jails, vms, and the truenas gui.

I'd like to be able to increase it to say 1 hour while I do the setup, and then drop it back to something more secure & reasonable like 5 minutes.

I can't find any documentation on this, or any setting via the GUI. This seems like something that should live on the System>General tab.

If anyone has insight on where I can make the change and have it stick across reboots, I'd be very grateful.
 

JV9

Dabbler
Joined
Aug 19, 2021
Messages
25

listhor

Contributor
Joined
Mar 2, 2020
Messages
133
I can see that nothing has been changed since above posts were published. It annoys me as well. Is there any way to change session timeout?
 

paradoxiom

Patron
Joined
Jun 16, 2015
Messages
239
Ah, I guess my google search ends here then.
 

majorgear

Dabbler
Joined
Mar 13, 2012
Messages
36
+1 for session timeout configuration because only the user knows their security requirements, vendors can suggest settings but they should never try to second-guess what the end user needs. One size does not fit all.
 

Redcoat

MVP
Joined
Feb 18, 2014
Messages
2,925
+1 for session timeout configuration because only the user knows their security requirements, vendors can suggest settings but they should never try to second-guess what the end user needs. One size does not fit all.
Go to the Jira link in post #3 above and add your vote there.
 
Top