Stay signed in

Signed in until somebody presses Sign out, with a secret that rotates on every use.

Stay signed in is a box on Loghound’s sign-in page that keeps a browser signed in to the panel until somebody presses Sign out. It needs the sign-in page mode, not the browser’s own prompt.

01 · How it works

The sign-in form offers it, and it is off by default. A browser that takes it is signed in with no idle timeout and no maximum session age: the session survives closing the browser, restarting the machine, and any amount of inactivity, and ends only when somebody presses Sign out.

What that costs, plainly

Whoever holds that browser profile has this panel, indefinitely. There is no timeout to save you from a lost laptop. Leave the box unticked on a shared or portable machine.

It is not just a long-lived cookie, because a long-lived cookie does not work: PHP deletes session files on a schedule of its own, and a cookie that outlives the file it names signs you out by accident — the exact thing the option exists to prevent. The cookie carries a lookup id and a secret, of which only a hash of the secret is stored.

real browsersecret rotates on every useacceptedlookup id stays the samecopied cookiepresents the old secretREPLAY DETECTEDunambiguously, not a guessEVERY TOKEN DESTROYEDevery browser signs in again, andthe sign-in page says why real browsersecret rotates on every useacceptedlookup id stays the samecopied cookiepresents the old secretREPLAY DETECTEDunambiguously, not a guessEVERY TOKEN DESTROYEDevery browser signs in again,and the sign-in page says why

Figure 1 — why the secret rotates and the lookup id does not. That asymmetry is exactly what makes a replayed secret detectable rather than indistinguishable from a stale cookie. “Once” has a width of thirty seconds, because several tabs revalidating on wake legitimately present one cookie at the same moment — and an alarm that fires every morning is not an alarm.

Six things revoke it: signing out (which revokes every token, not just this browser’s), signing in with the box unticked, the control in Settings that signs every remembered browser out, changing the password, changing the sign-in method, and turning two-factor on — because a token issued on the strength of one factor cannot survive as a way past two.

Signing in

Loghound is open source and MIT licensed. Questions about the Opensolr half — the account, the indexes, the plan — go to opensolr.com/contact; questions about the software itself belong on GitHub.

Loghound Documentation