# CakePHP 2.9 How is session expires field calculated?

**URL:** <https://discourse.cakephp.org/t/cakephp-2-9-how-is-session-expires-field-calculated/2063>\
**Category:** Need Help\
**Created:** [February 14, 2017, 1:49am UTC](https://discourse.cakephp.org/t/cakephp-2-9-how-is-session-expires-field-calculated/2063 "2017-02-14T01:49:29Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![etipaced](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/etipaced/32/3338_2.png) [@etipaced](https://discourse.cakephp.org/u/etipaced)\
**Post date:** [February 14, 2017, 1:49am UTC](https://discourse.cakephp.org/t/cakephp-2-9-how-is-session-expires-field-calculated/2063/1 "2017-02-14T01:49:29Z")

</div>

I’m using database sessions (cake\_sessions table) and the expires field is a UNIX timestamp that gets modified upon every page load. My Session.timeout & Session.cookieTimeout value are both 12 hours. When I view the cookie in my browser, it’s correctly set to 12 hours ahead from when I first initiate a new session. Likewise the expires field is also set for the same time.

However, the expires field in the cake\_sessions table is updated on every page load to 12 hours PAST THE CURRENT TIME. In other words, this field continually gets updated to go beyond the browser’s cookie timeout value. Why does it do this and won’t the browser terminate the session regardless once the original 12 hour timeout occurs?

Example to clarify:

- New session in browser & db set to 2/14/2017 5:50am.
- I reload the page and the browser’s cookie timeout is unchanged (2/14/2017 5:50am).
- However, the db “expires” field now reads 2/14/2017 5:51am (assuming I waited a full minute before refreshing)
