Docs/Security/Session lifetimes and idle timeout
DartRelay 2.1 documentation
Security

Session lifetimes and idle timeout

A portal left open on an unattended computer is an open door. This page explains how DartRelay signs people out when they stop using it, the longer limits on how long any sign-in can last, and what happens to the applications they had open.

Three clocks

Three separate limits decide how long someone stays signed in. It helps to keep them apart:

LimitWhat it measuresWhere you set it
Idle timeoutTime since the person last touched the keyboard or mouse. This is the one most people mean by "session timeout".Authentication → Security
Session lifetimeThe outer limits on a sign-in, however active the person is.System → Settings, Session Lifetime section
"Remember me"Whether the sign-in survives the browser being closed and reopened.The person's choice on the sign-in page

The idle timeout

When nobody has typed or moved the mouse for the number of minutes you set, DartRelay signs the person out, closes their applications and returns them to the sign-in page. The portal and the admin console each have their own value.

Setting it

  1. Open the Security page. Go to Authentication → Security and find the session timeout card.
  2. Enter the minutes for the user portal. 0 switches the idle timeout off for the portal.
  3. Enter the minutes for the admin console. 0 switches it off for the console.
  4. Save the card. The new values apply straight away; nobody needs to sign in again for them to take effect.
FieldWhat it doesDefault
User portal (minutes)Minutes without activity before a portal visitor is signed out. 0 = off.15
Admin console (minutes)Minutes without activity before the console signs an administrator out. 0 = off.15

What counts as activity

Activity means real keyboard and mouse input in the browser — on the portal page itself and inside every application or desktop tab the person has open. Someone typing in a published application is active, even though the portal page around it has not changed. A browser tab that is simply left open does not count.

If the person has several portal tabs open, activity in any of them keeps the sign-in alive.

Which number applies

The number that applies depends on which part of DartRelay is being used: the console's number for the admin console, the portal's number for everything else. An administrator using the portal is governed by the portal's number while they are there, and by the console's number when they open the console.

What the person sees

  1. Shortly before the limit, a 30-second countdown appears with two buttons: Keep Alive, which continues the session, and Leave, which signs out now.
  2. If nobody responds, the screen shows "Signed out after N minutes without activity" and the portal returns to the sign-in page.

Because DartRelay records activity about once a minute, the actual sign-out can come up to a minute after the limit.

What happens to running applications

When the idle timeout signs someone out, DartRelay also closes their application and desktop tabs, so whoever sits down at the computer next does not find them still open. Specifically:

Whether a disconnected Windows session is later signed out is decided on the host — by Windows' own session limits, or by the host option to sign out of Windows when the last tab closes. See Host session options.

Tip

Pick the portal value with your users' work in mind. Fifteen minutes suits most offices. Shared or public computers — a ward terminal, a reception desk — deserve a shorter value; people who read long documents without touching the mouse may need a longer one.

Session lifetime

Beyond the idle timeout, the Session Lifetime section of System → Settings sets outer limits that apply however active someone is.

FieldWhat it doesDefault
Maximum Session AgeThe longest a session can run before it is ended, whatever the activity.—
Admin Cookie LifetimeHow long an administrator's console sign-in lasts.—

Saving System Settings sends the security-settings message to the Admin Notification Emails list.

"Remember me"

Ticking "Remember me" on the sign-in page means the person can close the browser and reopen it without signing in again, for up to 30 days. It does not switch the idle timeout off: a remembered sign-in that sits unused past the idle limit is still signed out.

Quiet sessions stay connected

An application that is open but not changing — a form waiting for input, a report being read — sends little or nothing over the connection. DartRelay keeps such connections alive on its own, in both directions, so a quiet session is never mistaken for a dead one and closed. This is separate from the idle timeout above, which looks at the person, not the connection.

The reverse is handled too: if a host is switched off or drops off the network mid-session, DartRelay notices that the host has stopped answering and ends the tab, rather than leaving a frozen picture on screen.

Guest sessions when guest access is switched off New in 2.0

If you switch guest access off, or change an address so it no longer admits visitors without a sign-in, browsers already signed in as the guest are signed out on their next request and their applications close, in the same way as an idle sign-out. See Guest access without a sign-in.

Example

A clinic runs DartRelay for reception terminals and for staff working from home. The administrator sets the portal idle timeout to 10 minutes, because reception terminals are shared and in a public area, and the console to 15 minutes. On the hosts, they switch on signing out of Windows when the last tab closes for the shared reception account, so each new person starts with a fresh Windows session. Home workers who step away for a coffee come back to the sign-in page; when they launch their application again, it reconnects to their disconnected Windows session with their work intact.

If something goes wrong

Nobody is ever signed out

Check that the value on the session timeout card is not 0 for the area you are testing — the portal and the console are separate. Remember that activity in any open portal tab keeps the sign-in alive, and allow up to a minute past the limit.

Someone was signed out while they were working

Activity is measured from keyboard and mouse input in the browser. Watching a video or reading without touching anything is not activity. Raise the portal value, or ask them to press Keep Alive when the countdown appears.

After an idle sign-out, the application did not reopen where it was

The Windows session may have been signed out on the host since — by a Windows disconnection limit, or by the host option to sign out when the last tab closes. Check the host's settings. See Host session options.

A session tab ends on its own after the host restarts

That is expected: when a host stops answering, DartRelay ends the tab rather than show a frozen screen. The person can launch the resource again once the host is back.

Still stuck? Email support@dartinnovations.com with what you were doing, what you expected and what you saw. A screenshot helps.