Actions
Story #17
openEpic #1: Access Control & Identity Management
Implement Secure Session Management and Timeouts
Status:
New
Priority:
Medium
Assignee:
-
Target version:
-
Start date:
12/24/2025
Due date:
% Done:
0%
Estimated time:
Acceptance Criteria:
1. Session timeout is configurable
2. Secure cookies are enforced
3. Sessions are invalidated on logout
4. Session hijacking protections are enabled
DOR:
No
Story Points:
Work Type:
Feature
User Impact:
Technical Area:
Release Narrative:
Planned Sprint:
Completed In Sprint:
Spillover Reason:
Deployment Reference URL:
Description
User Story:
As a security administrator,
I want user sessions to expire automatically,
So that unattended sessions cannot expose PHI.
No data to display
Actions