@SRAZKVT@tech.lgbt
how long should i make it so that session gets invalidated ? for idle, owasp recommends 2-5 minutes for high value systems, 15-30 minutes for low value systems, and for absolute, after 4-8 hours after the session is created
but that will log you out all the fucking time won't it ? won't that be annoying ? how much time do most modern platforms take before logging you out ? do they even invalidate your session at all and instead spit on owasp's recommendations ?