Skip to content

Conversation

@rullzer
Copy link
Member

@rullzer rullzer commented Jan 23, 2019

backport of #13757

If the remember_login_cookie_lifetime is set to 0 this means we do not
want to use remember me at all. In that case we should also not creatae
a remember me cookie and should create a proper temp token.

Further this specifies that is not 0 the remember me time should always
be larger than the session timeout. Because else the behavior is not
really defined.

Signed-off-by: Roeland Jago Douma <[email protected]>
@rullzer
Copy link
Member Author

rullzer commented Jan 24, 2019

Also 👍 from me

@rullzer rullzer merged commit c7fd71e into stable14 Jan 24, 2019
@rullzer rullzer deleted the backport/13747/stable14 branch January 24, 2019 17:32
@MorrisJobke
Copy link
Member

backport of #13757

Not really - it's a backport of #13747

@MorrisJobke MorrisJobke mentioned this pull request Jan 30, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review Waiting for reviews bug

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants