<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <title>liferay session not expired after timeout.</title>
  <link rel="self" href="https://liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=112282232" />
  <subtitle>liferay session not expired after timeout.</subtitle>
  <id>https://liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=112282232</id>
  <updated>2026-04-05T11:58:37Z</updated>
  <dc:date>2026-04-05T11:58:37Z</dc:date>
  <entry>
    <title>RE: liferay session not expired after timeout.</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=112283174" />
    <author>
      <name>David H Nebinger</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=112283174</id>
    <updated>2019-02-08T22:42:56Z</updated>
    <published>2019-02-08T22:42:56Z</published>
    <summary type="html">There may still be a session in place, but contents might have been wiped.&lt;br /&gt;&lt;br /&gt;Have you verified if the session contains something you&amp;#39;re worried about?&lt;br /&gt;&lt;br /&gt;Also if you have set the session.phishing.protected.attributes property in portal-ext.properties, these are carried over when session is created at login and might do it for logout too, although I haven&amp;#39;t tested that.</summary>
    <dc:creator>David H Nebinger</dc:creator>
    <dc:date>2019-02-08T22:42:56Z</dc:date>
  </entry>
  <entry>
    <title>liferay session not expired after timeout.</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=112282231" />
    <author>
      <name>Durai pandian</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=112282231</id>
    <updated>2019-02-08T20:22:39Z</updated>
    <published>2019-02-08T20:22:39Z</published>
    <summary type="html">Hello All,&lt;br /&gt;​​​​​​​&lt;br /&gt;        I have set the below session configs.&lt;br /&gt;&lt;br /&gt;session.timeout=15&lt;br /&gt;session.timeout.warning=13&lt;br /&gt;session.timeout.auto.extend=false&lt;br /&gt;session.timeout.redirect.on.expire=true&lt;br /&gt;In web.xml the timeout is set to 15. &lt;br /&gt;&lt;br /&gt;I have created a hook to session_timeout.jspf to set &amp;#34;sessionRedirectUrl&amp;#34; to a public page where the timeout error message displayed.&lt;br /&gt;&lt;br /&gt;The output I got is very strange. After timeout the user redirected to the expected page but I can see still the session is there. It is not get invalidated.&lt;br /&gt;Please help me what I have missed. &lt;br /&gt;&lt;br /&gt;​​​​​​​Thanks in advance.</summary>
    <dc:creator>Durai pandian</dc:creator>
    <dc:date>2019-02-08T20:22:39Z</dc:date>
  </entry>
</feed>
