# Request long session for frontend login

**URL:** <https://forum.getkirby.com/t/request-long-session-for-frontend-login/18514>\
**Category:** Questions\
**Tags:** v3\
**Created:** [June 11, 2020, 5:50pm UTC](https://forum.getkirby.com/t/request-long-session-for-frontend-login/18514 "2020-06-11T17:50:05Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![rzschoch](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/rzschoch/32/8835_2.png) [@rzschoch](https://forum.getkirby.com/u/rzschoch)\
**Post date:** [June 11, 2020, 5:50pm UTC](https://forum.getkirby.com/t/request-long-session-for-frontend-login/18514/1 "2020-06-11T17:50:05Z")

</div>

I’m trying to offer my users a long session option while they are logging in (also known as: keep me logged in).

As a first step I updated my login code as described [here](https://getkirby.com/docs/guide/sessions#requesting-a-long-session):  
`$user->login($password, $kirby->session(['long' => true]));`

…and changed the global [durationLong setting](https://getkirby.com/docs/reference/system/options/session#durationlong) to a duration of 5 seconds for testing purposes.

However, when I log in now, I don’t just stay logged in for the 5 seconds. I also stay logged in after minutes, even if I close the tab and reopen it.

Am I missing something here?

---

<div class="post-metadata">

**Author:** ![texnixe](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/texnixe/32/5754_2.png) [@texnixe](https://forum.getkirby.com/u/texnixe)\
**Post date:** [June 11, 2020, 5:55pm UTC](https://forum.getkirby.com/t/request-long-session-for-frontend-login/18514/2 "2020-06-11T17:55:30Z")

</div>

That probably doesn’t make sense. Have you read this section about sessions: [https://getkirby.com/docs/guide/sessions#the-session-lifecycle](https://getkirby.com/docs/guide/sessions#the-session-lifecycle)

---

<div class="post-metadata">

**Author:** ![rzschoch](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/rzschoch/32/8835_2.png) [@rzschoch](https://forum.getkirby.com/u/rzschoch)\
**Post date:** [June 11, 2020, 6:15pm UTC](https://forum.getkirby.com/t/request-long-session-for-frontend-login/18514/3 "2020-06-11T18:15:49Z")

</div>

Yes, I have, but probably do not understand it right.

> There are also so-called “long sessions”. They don’t have a timeout and expire after two weeks by default. The expiry time can be changed with the [`session.durationLong` option].

What I want is to change the expiry time to 1 week in the end but would like to test it with a much shorter time before. What would be the recommended way to do this with the `$user->login()` method?

---

<div class="post-metadata">

**Author:** ![texnixe](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/texnixe/32/5754_2.png) [@texnixe](https://forum.getkirby.com/u/texnixe)\
**Post date:** [June 11, 2020, 6:33pm UTC](https://forum.getkirby.com/t/request-long-session-for-frontend-login/18514/4 "2020-06-11T18:33:21Z")

</div>

I don’t know. Ping @lukasbestle…

---

<div class="post-metadata">

**Author:** ![lukasbestle](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/lukasbestle/32/11437_2.png) [@lukasbestle](https://forum.getkirby.com/u/lukasbestle)\
**Post date:** [June 11, 2020, 7:21pm UTC](https://forum.getkirby.com/t/request-long-session-for-frontend-login/18514/5 "2020-06-11T19:21:13Z")

</div>

The reason why you don’t see the effect for a `durationLong` value of five seconds is most likely the way you are testing it:

When you visit the Panel login page, Kirby will automatically create a session to store the CSRF token. Because the user has not yet decided whether they want a long or a normal session, the session will for now be of normal length (= two hours). If you then log in to the Panel and check the “keep me logged in” checkbox, Kirby will extend the session duration to the configured value of `durationLong` – however it will _not_ shorten the duration of an already existing session. So Kirby will use the two hours and not the five seconds. That’s an example with the Panel, but the same most likely also applies to custom login forms (depending on how they are implemented). In any case it’s not supported to have a shorter `durationLong` than `durationNormal`.

If you want to verify whether your code works, it’s better to check directly in your browser’s dev tools. In Safari it will for example look like this:

 ![Bildschirmfoto 2020-06-11 um 21.20.12](https://europe1.discourse-cdn.com/flex017/uploads/getkirby/original/2X/e/ef0cf2d8ba034cbeecac3cff6d9152db1e8497d0.png)

---

<div class="post-metadata">

**Author:** ![rzschoch](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/rzschoch/32/8835_2.png) [@rzschoch](https://forum.getkirby.com/u/rzschoch)\
**Post date:** [June 12, 2020, 9:49am UTC](https://forum.getkirby.com/t/request-long-session-for-frontend-login/18514/6 "2020-06-12T09:49:30Z")

</div>

Thanks a lot for the extensive explanation. It all works like you described.

That’s my final line of code for a long session login:  
`$user->login($password, ['long' => true]);`

---

<div class="post-metadata">

**Author:** ![lukasbestle](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/lukasbestle/32/11437_2.png) [@lukasbestle](https://forum.getkirby.com/u/lukasbestle)\
**Post date:** [June 12, 2020, 10:09am UTC](https://forum.getkirby.com/t/request-long-session-for-frontend-login/18514/7 "2020-06-12T10:09:13Z")

</div>

Awesome! BTW: If you are implementing a frontend login form, it’s better to use the following:

```php
$user = $kirby->auth()->login($email, $password, /* $long = */ true);

```

The advantage is that this will give you brute-force protection for free.
