mirror of
https://github.com/simstudioai/sim.git
synced 2026-09-24 15:45:35 +08:00
feat(auth): org session policies — lifetime/idle limits, org-wide revocation (#5862)
* feat(auth): org session policies — lifetime/idle limits, org-wide revocation, cookie-cache versioning * refactor(auth): consolidate session-policy clamp semantics, shared security-policy version module, canonical bounds, docs * polish(session-policy): cleanup pass — muted field labels, spinner reset, state tracker, response-seeded baseline, comment trims * fix(session-policy): govern member sessions by membership (closes revoke cookie-cache hole), normalize createdAt, remount on org switch, sync audit mock * fix(session-policy): clamp pre-join sessions on invite acceptance, normalize expiresAt, sync unified nav test * fix(session-policy): invalidate membership cache on removal/transfer, spare impersonator sessions in revoke-all, raise idle floor to 2x cookie window * fix(session-policy): resolve governing org by membership only — activeOrganizationId goes stale across transfer/leave * fix(session-policy): atomic policy save + eager clamp, asymmetric membership TTL, admin-add cache invalidation * fix(session-policy): org-scoped cookie version string, atomic revoke delete+bump * fix(session-policy): plan-gate effective policy so downgraded orgs stop enforcing automatically * chore(session-policy): drop dead bumpSecurityPolicyVersion helper — call sites bump transactionally * fix(session-policy): unify join paths on applySessionPolicyToNewMember; final audit polish (dead exports, response bound, test name)
This commit is contained in:
@@ -3,6 +3,7 @@
|
||||
"pages": [
|
||||
"index",
|
||||
"sso",
|
||||
"session-policies",
|
||||
"access-control",
|
||||
"custom-blocks",
|
||||
"whitelabeling",
|
||||
|
||||
@@ -0,0 +1,76 @@
|
||||
---
|
||||
title: Session Policies
|
||||
description: Set session lifetime limits and sign out every member of your organization at once
|
||||
---
|
||||
|
||||
import { FAQ } from '@/components/ui/faq'
|
||||
|
||||
Session Policies let organization owners and admins on Enterprise plans control how long member sign-in sessions last, and sign out every member org-wide in one action. Policies apply to every member of the organization on every device.
|
||||
|
||||
---
|
||||
|
||||
## Setup
|
||||
|
||||
Go to **Settings → Security → Session policies** in your organization settings.
|
||||
|
||||
Both limits are optional. Leave a field empty to keep the default behavior: sessions last 30 days and extend automatically while a member stays active.
|
||||
|
||||
---
|
||||
|
||||
## Settings
|
||||
|
||||
### Max session lifetime
|
||||
|
||||
Caps how long a session can exist from the moment a member signs in, regardless of activity. When the limit is reached, the member must sign in again.
|
||||
|
||||
Use this to enforce periodic re-authentication — for example, a value of `168` requires everyone to sign in again at least weekly. Accepts 1 to 8760 hours (1 year).
|
||||
|
||||
### Idle timeout
|
||||
|
||||
Signs a member out after this many hours without activity. Activity extends the session, so members who use Sim regularly stay signed in; dormant sessions expire.
|
||||
|
||||
Accepts 48 to 8760 hours. The 48-hour minimum exists because session activity is recorded at most once per day — a shorter window could sign out members who are actively working.
|
||||
|
||||
### Sign out all members
|
||||
|
||||
The **Sign out all members** action immediately revokes every member session in the organization except your own. Members are signed out on their next request — typically within a minute — and must sign in again.
|
||||
|
||||
Use this after a security incident, an offboarding wave, or before tightening a policy you want to take effect everywhere at once.
|
||||
|
||||
---
|
||||
|
||||
## How enforcement works
|
||||
|
||||
- **New sign-ins** get an expiry that respects the policy from the moment the session is created.
|
||||
- **Existing sessions** are shortened immediately when you save a tighter policy — no member keeps a longer session than the new policy allows.
|
||||
- **Loosening a policy never extends existing sessions.** Members pick up the longer limit the next time they sign in.
|
||||
- Changes propagate to active members within about a minute; there is no need to redeploy or wait for sessions to naturally expire.
|
||||
|
||||
---
|
||||
|
||||
## FAQ
|
||||
|
||||
<FAQ
|
||||
items={[
|
||||
{
|
||||
question: 'Do session policies apply to SSO sign-ins?',
|
||||
answer:
|
||||
'Yes. Sessions created through SSO follow the same lifetime and idle limits as any other sign-in method. Your identity provider may enforce its own, stricter session rules on top.',
|
||||
},
|
||||
{
|
||||
question: 'What happens to a member who is working when their session expires?',
|
||||
answer:
|
||||
'They are redirected to sign in again on their next request. Unsaved workflow changes in the editor are preserved by the collaborative canvas, which continuously syncs edits.',
|
||||
},
|
||||
{
|
||||
question: 'Does "Sign out all members" affect API keys or running workflows?',
|
||||
answer:
|
||||
'No. It revokes browser sign-in sessions only. API keys, deployed workflows, webhooks, and schedules keep working — manage those separately from the API keys settings.',
|
||||
},
|
||||
{
|
||||
question: 'Why is the minimum idle timeout 48 hours?',
|
||||
answer:
|
||||
'Session activity is recorded at most once per 24 hours for performance. The minimum is twice that window so a member who stays active always registers activity before the idle limit can expire their session.',
|
||||
},
|
||||
]}
|
||||
/>
|
||||
Reference in New Issue
Block a user