Thursday, April 23, 2009

Session Timeout on Login Screen

I was just at a website where I didn't remember the password and had to look it up. When I found it, I switched back to the browser and typed in my username and password. Clicked Login. What I got was a page saying that my session had timed out and I had to click a link to return to the login page.

That's stupid. There's no security value at all in expiring a session of someone who hasn't logged in yet. And since the site is absolutely not dynamic at all until after you login, there really isn't any value in keeping a session for someone who hasn't logged in yet. So if there's going to be a session assigned to me before I log in, and it's worthless, then don't bother me with a message saying it expired. Just make me a new one, and then take me to my homepage. Or, if I got the password wrong, then make me a new one and take me back to the login screen immediately. But I really don't care that the worthless session expired, and I'm really annoyed at having to read that and click one more time just to try again.


No comments:

Post a Comment