Skip to content

feat(admin): add Keep me signed in duration to Security settings - #1431

Merged
solarssk merged 2 commits into
mainfrom
feature/remember-me-security-setting
Sep 24, 2026
Merged

solarssk merged 2 commits into
mainfrom
feature/remember-me-security-setting

Conversation

@solarssk

Copy link
Copy Markdown
Owner

Description

Business context. The "Keep me signed in" option for operators (#1430) has a configurable duration, but a superadmin could only change it through the system-settings API or an environment variable. The Security settings page now has a field for it, so a superadmin can lengthen it for a multi-day event, shorten it, or set it to 0 to hide the sign-in checkbox, without touching the server.

Technical changes.

  • Admin UI: new numeric row "Operator "Keep me signed in" duration (days)" on the Security card, between the operator inactivity timeout and "Remember device duration". Range 0 to 14, taken from the shared MAX_OPERATOR_REMEMBER_ME_DAYS constant through the browser-safe @admitto/auth/constants subpath. The field is read-only and shows the environment badge when OPERATOR_REMEMBER_ME_DAYS locks it.
  • API types and patch builder: SystemSettingsDto and PatchSystemSettingsBody include operator_remember_me_days; buildSecurityPatchBody sends only the changed value (clamped to 0 to 14, an empty field keeps the saved value) and skips it when locked. No backend change: GET/PATCH /api/admin/system-settings already handle the key since feat(auth): add "Keep me signed in" for operator sign-in #1430.
  • Tests: a new SecurityPanel.rememberMe component test, patch-builder tests, and the shared settings fixtures updated with the new field.
  • Docs: CHANGELOG entry and the Organisation settings wiki page.

How to test

  1. npm test -w @admitto/admin (317 files, 4365 tests pass locally), npm run build -w @admitto/admin, npm run docs:check.
  2. As a superadmin open Organisation settings, then Security. Change the new field to 7 and save; the sign-in page still shows the checkbox and a new operator sign-in gets a 7 day session. Set it to 0 and save; the checkbox disappears from the sign-in page.
  3. Start the server with OPERATOR_REMEMBER_ME_DAYS=5: the field shows 5 and is read-only with the environment badge.

What stays / known limitations

  • Existing remembered sessions keep the lifetime they were created with; a new value applies to sessions started afterwards (the idle window of a remembered session follows the current setting, and is dropped back to the normal operator inactivity timeout when the option is switched to 0).
  • No warning threshold on the field: the 14 day cap already bounds the exposure of a lost device.

Documentation impact

  • Wiki updated
  • No Wiki update needed - explain why

Checklist

  • No secrets / keys / passwords in the diff
  • No real personal data (seed/sample data uses synthetic @example.com addresses)
  • Tests pass locally (npm test; optional: npm run coverage to match CI)
  • New or changed functionality is covered by tests added to the automated suite
  • New fields containing personal data are justified and minimised (no personal data added)
  • No PII in logs; token/QR contains no personal data
  • DB schema changes include a migration (no schema change in this PR)

🤖 Generated with Claude Code

Superadmins can now change how long a remembered operator session lasts, or set 0 to hide the sign-in checkbox, from Security settings instead of the system-settings API or an environment variable.

- New numeric row "Operator "Keep me signed in" duration (days)" (0 to 14), read-only when OPERATOR_REMEMBER_ME_DAYS locks it.
- Extend SystemSettingsDto, PatchSystemSettingsBody and the patch builder.
- Document the field on the Organisation settings wiki page and in the changelog.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@solarssk solarssk added this to the 0.7.4 milestone Sep 24, 2026
@solarssk solarssk added type: feature New capability or user-facing functionality prio: medium Should land in current milestone but not a blocker area: admin Admin application — staff and organisation settings labels Sep 24, 2026
@solarssk solarssk self-assigned this Sep 24, 2026
@solarssk

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8c63dc074c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread apps/admin/src/settings/SecurityPanel.tsx
@codecov

codecov Bot commented Sep 24, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ All tests successful. No failed tests found.

📢 Thoughts on this report? Let us know!

… settings

The env catalog still said the setting had no admin UI. Point it at Settings > Security, like the other settings that have a field there, and regenerate deploy/ENV.md.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@solarssk

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Breezy!

Reviewed commit: af4a4d3420

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@sonarqubecloud

Copy link
Copy Markdown

@solarssk
solarssk merged commit 49b0616 into main Sep 24, 2026
24 checks passed
@solarssk
solarssk deleted the feature/remember-me-security-setting branch September 24, 2026 11:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: admin Admin application — staff and organisation settings prio: medium Should land in current milestone but not a blocker type: feature New capability or user-facing functionality

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant