Fix: mobile session timeouts (M2-11149, M2-11150) - #2266
Merged
Merged
Conversation
|
This pull request is automatically being deployed by Amplify Hosting (learn more). |
sricharan-varanasi
force-pushed
the
fix/mobile-session-timeouts
branch
from
September 16, 2026 03:50
b5669a2 to
f1f6717
Compare
adeiji
approved these changes
Sep 16, 2026
adeiji
left a comment
Contributor
There was a problem hiding this comment.
Looks good @sricharan-varanasi !
Merged
17 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
📝 Description
🔗 Jira Ticket M2-11149
🔗 Jira Ticket M2-11150
Session timeout fixes for mobile browsers, ported from the same fixes on web. Android
pauses background tabs, so a signed-in tab misses its own idle logout and wakes up
acting on stale state.
Changes include:
login-page tab is no longer blocked by a session that has already timed out.
the banner clears on time without a reload.
logged out cannot end the new one immediately.
or keeping itself alive on the new session's clock.
through "Stay logged in" used to wake with the old deadline and end the session for
everyone.
🪤 Peer Testing
Best tested on Android Chrome with two tabs. A shorter
VITE_IDLE_TIMEOUT_MINmakesthis practical.
Sign in on Tab A, leave Tab B on the login page, and stay on Tab B past the idle
timeout.
Expected outcome: the yellow banner on Tab B disappears at the deadline.
Reload Tab B and sign in.
Expected outcome: sign-in works and stays signed in, with no "automatically
logged out" banner.
Switch back to Tab A.
Expected outcome: Tab A shows the login page with "You signed in with another
tab or window". Tab B stays signed in.
With both tabs signed in and the warning showing, tap "Stay logged in" on Tab A,
wait out the original countdown, then switch to Tab B.
Expected outcome: both tabs stay signed in.
Desktop check: sign in on two tabs, then log out from one.
Expected outcome: the other tab goes to the login page with no "automatically
logged out" banner.
✏️ Notes
familyclaim intokens. Confirmed on dev; worth confirming for staging and prod before release.
deadline, so its refresh token stays valid until it expires. Tracked separately.
events they end in are already tracked.
✅ Checklist
Functionality
Testing
Security & Data Privacy
Logging/Monitoring
Performance
Readability
Change Safety
Backend changes are backwards compatible with old clients, or it is well known they are not and a deployment/rollout plan is in place. This include backend changes being compatible with old mobile app versions, as well as applet versioning within Curious.Destructive database migrations are rolled out in stages. For example, renaming a column means adding a new column and migrating the existing data to that columns in one deployment. Then monitoring to ensure that field isn't used, and finally removing that old column in a separate deployment.