security: forcibly expire old sessions #69

Closed
justcool393 wants to merge 1 commits from <deleted>:session-expiration into master
1 changed files with 7 additions and 0 deletions

View File

@ -22,6 +22,13 @@ def get_logged_in_user():
v = client.user
v.client = client
else:
session_expiration = session.get("lo_user_expiration")
if session_expiration:
if time.time() - session_expiration > SESSION_LIFETIME:
session.pop("lo_user", None)
else:
session["lo_user_expiration"] = time.time() + SESSION_LIFETIME
lo_user = session.get("lo_user")
if lo_user:
id = int(lo_user)