feat(admin): add Keep me signed in duration to Security settings - #1431
Conversation
Superadmins can now change how long a remembered operator session lasts, or set 0 to hide the sign-in checkbox, from Security settings instead of the system-settings API or an environment variable. - New numeric row "Operator "Keep me signed in" duration (days)" (0 to 14), read-only when OPERATOR_REMEMBER_ME_DAYS locks it. - Extend SystemSettingsDto, PatchSystemSettingsBody and the patch builder. - Document the field on the Organisation settings wiki page and in the changelog. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8c63dc074c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
… settings The env catalog still said the setting had no admin UI. Point it at Settings > Security, like the other settings that have a field there, and regenerate deploy/ENV.md. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
@codex review |
|
Codex Review: Didn't find any major issues. Breezy! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|



Description
Business context. The "Keep me signed in" option for operators (#1430) has a configurable duration, but a superadmin could only change it through the system-settings API or an environment variable. The Security settings page now has a field for it, so a superadmin can lengthen it for a multi-day event, shorten it, or set it to 0 to hide the sign-in checkbox, without touching the server.
Technical changes.
MAX_OPERATOR_REMEMBER_ME_DAYSconstant through the browser-safe@admitto/auth/constantssubpath. The field is read-only and shows the environment badge whenOPERATOR_REMEMBER_ME_DAYSlocks it.SystemSettingsDtoandPatchSystemSettingsBodyincludeoperator_remember_me_days;buildSecurityPatchBodysends only the changed value (clamped to 0 to 14, an empty field keeps the saved value) and skips it when locked. No backend change:GET/PATCH /api/admin/system-settingsalready handle the key since feat(auth): add "Keep me signed in" for operator sign-in #1430.SecurityPanel.rememberMecomponent test, patch-builder tests, and the shared settings fixtures updated with the new field.How to test
npm test -w @admitto/admin(317 files, 4365 tests pass locally),npm run build -w @admitto/admin,npm run docs:check.OPERATOR_REMEMBER_ME_DAYS=5: the field shows 5 and is read-only with the environment badge.What stays / known limitations
Documentation impact
Checklist
@example.comaddresses)npm test; optional:npm run coverageto match CI)🤖 Generated with Claude Code