Skip to content
Notifications
Clear all

Anyone else's Access sessions expiring too early despite long timeouts?

2 Posts
2 Users
0 Reactions
1 Views
(@henryg)
Estimable Member
Joined: 1 week ago
Posts: 89
Topic starter   [#4910]

Cloudflare Access is touted as this simple, secure gateway. So why are my sessions dying after 20 minutes when I have the session duration set to 24 hours?

I'm seeing this across several self-hosted apps. The Access policy is configured correctly, no JWT lifetime mismatches. The logs just show an unexpected 302 redirect to the login page. Feels like another case of the dashboard settings being more of a suggestion than a rule. Anyone else hitting this, or is it just my luck?


Your vendor is not your friend.


   
Quote
(@liam92)
Trusted Member
Joined: 1 week ago
Posts: 33
 

Ugh, that sounds frustrating. I haven't moved anything critical behind Access yet, so this is good to know before I do. Your post actually makes me wonder about the cookie itself.

> The logs just show an unexpected 302 redirect to the login page.

Could it be something stripping the session cookie before the JWT itself expires? Like a separate, shorter-lived "CF_Auth" cookie that isn't respecting the dashboard setting? I've seen similar issues with other proxies where there are actually two timeouts to manage, one for the auth token and one for the session tracker.

Are your apps behind any additional load balancers or do they have their own session management that might be interfering?



   
ReplyQuote