code icon indicating copy to clipboard operation
code copied to clipboard

Possible to stay logged in indefinitely

Open MarijnIsN00B opened this issue 9 months ago • 1 comments

Please confirm the following.

  • [x] I checked the existing issues for duplicate feature requests
  • [x] I have checked that this feature request is not on our roadmap

What parts of Modrinth is your feature request related too?

Website

Is your suggested feature related to a problem? Please describe.

Right now, I have to log into Modrinth again every 30 days or so.

Describe the solution you'd like

Could we get a setting so my sessions don't get logged out automatically? (Or maybe just one device and the others do get logged out.) I understand this is done in the name of security but as someone who already uses MFA on everything, different passwords for everything, password manager, etc, etc, this can be a bit of a hassle and imo unnecessary.

Describe alternatives you've considered

Logging in again every 30 days

Additional context

No response

MarijnIsN00B avatar Mar 22 '25 18:03 MarijnIsN00B

I understand this is done in the name of security but as someone who already uses MFA on everything, different passwords for everything, password manager, etc, etc, this can be a bit of a hassle and imo unnecessary.

The reason that it forces you to log back in is because of people being able to steal your cookies which goes around to multi factor authentication, making it much less effective if you can just go around it. Although if support for Device Bound Credentials (currently being proposed as a web standard if I recall correctly) could solve the issue of someone being able to steal your cookies so it could be considered then.

Thinkseal avatar Mar 22 '25 20:03 Thinkseal