-
Notifications
You must be signed in to change notification settings - Fork 7
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
As a user who has left my computer, I should be logged out after a period of inactivity, so my account remains secure (AC-2(5), AC-12) #79
Comments
Seems like there's supposed to be a 15 minute session lock, and a 30 minute session termination timeout. Asking for clarity from IPT on the practical differences between lock and termination for a web app. |
We can ignore the 15 minute session lock and only implement the 30 minute session termination |
Added screen lock to list of exclusions. Assigned 8 points based on discussion with @kryswisnaskas and @jasalisbury |
Definition of done:
|
User story:
As a user who has left my computer for 25 minutes or longer, I want the system to log me out of Smart Hub so the site remains secure.
Acceptance Criteria:
Considerations:
Exclusions:
The text was updated successfully, but these errors were encountered: