Skip to content

Possible to stay logged in indefinitely #3417

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
2 tasks done
MarijnIsN00B opened this issue Mar 22, 2025 · 1 comment
Open
2 tasks done

Possible to stay logged in indefinitely #3417

MarijnIsN00B opened this issue Mar 22, 2025 · 1 comment
Labels
enhancement New feature or request

Comments

@MarijnIsN00B
Copy link

Please confirm the following.

  • I checked the existing issues for duplicate feature requests
  • I have checked that this feature request is not on our roadmap

What parts of Modrinth is your feature request related too?

Website

Is your suggested feature related to a problem? Please describe.

Right now, I have to log into Modrinth again every 30 days or so.

Describe the solution you'd like

Could we get a setting so my sessions don't get logged out automatically? (Or maybe just one device and the others do get logged out.)
I understand this is done in the name of security but as someone who already uses MFA on everything, different passwords for everything, password manager, etc, etc, this can be a bit of a hassle and imo unnecessary.

Describe alternatives you've considered

Logging in again every 30 days

Additional context

No response

@MarijnIsN00B MarijnIsN00B added the enhancement New feature or request label Mar 22, 2025
@Thinkseal
Copy link

I understand this is done in the name of security but as someone who already uses MFA on everything, different passwords for everything, password manager, etc, etc, this can be a bit of a hassle and imo unnecessary.

The reason that it forces you to log back in is because of people being able to steal your cookies which goes around to multi factor authentication, making it much less effective if you can just go around it. Although if support for Device Bound Credentials (currently being proposed as a web standard if I recall correctly) could solve the issue of someone being able to steal your cookies so it could be considered then.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Development

No branches or pull requests

2 participants