# Session expires automatic redirection to login

**URL:** <https://discourse.cakephp.org/t/session-expires-automatic-redirection-to-login/8140>\
**Category:** Need Help\
**Created:** [July 29, 2020, 8:30am UTC](https://discourse.cakephp.org/t/session-expires-automatic-redirection-to-login/8140 "2020-07-29T08:30:11Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![bichomen](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/bichomen/32/1070_2.png) [@bichomen](https://discourse.cakephp.org/u/bichomen)\
**Post date:** [July 29, 2020, 8:30am UTC](https://discourse.cakephp.org/t/session-expires-automatic-redirection-to-login/8140/1 "2020-07-29T08:30:12Z")

</div>

When I log out, the redirection to the login is executed, this is correct, but when the session expires nothing happens, I cannot access other pages but there is no notice of expired session.

I want that when the session expires it is automatically redirected to the login or at least that when a user gives a link it is redirected to the login. Where and how do I configure this? Since I have been looking at the documentation, but I do not see anywhere how to implement this. Thank you

In cakephp 3.6

---

<div class="post-metadata">

**Author:** ![bizdev](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/bizdev/32/1951_2.png) [@bizdev](https://discourse.cakephp.org/u/bizdev)\
**Post date:** [July 30, 2020, 12:08pm UTC](https://discourse.cakephp.org/t/session-expires-automatic-redirection-to-login/8140/3 "2020-07-30T12:08:09Z")

</div>

Hi @bichomen,

Please add your auth configuration code for more understanding.

---

<div class="post-metadata">

**Author:** ![bichomen](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/bichomen/32/1070_2.png) [@bichomen](https://discourse.cakephp.org/u/bichomen)\
**Post date:** [July 30, 2020, 5:42pm UTC](https://discourse.cakephp.org/t/session-expires-automatic-redirection-to-login/8140/4 "2020-07-30T17:42:16Z")

</div>

ok

AppController:

```
  $this->loadComponent('RequestHandler', [
            'enableBeforeRedirect' => false,
        ]);
        $this->loadComponent('Flash');
        $this->loadComponent('Auth',[
          'authorize' => ['Controller'],
          'authenticate' => [
            'Form' => [
              'finder' => 'auth',
              'fields' => [
                'username' => 'email',
                'password' => 'password'
              ],
              'userModel' => 'Users'
            ]
          ],
          'loginAction' => [
            'controller' => 'Users',
            'action' => 'login'
          ],
          'loginRedirect' => [
            'controller' => 'Efemerides',
            'action' => 'index'
          ],
          'logoutRedirect' => [
            'controller' => 'Users',
            'action' => 'login'
          ],
          'unauthorizedRedirect' => $this->referer()
        ]);

```

In UserController:

```
  public function logout() {
      $url = '/users/login/';
      $this->Auth->logout();
      $this->request->session()->destroy();
      return $this->redirect($url);
  }

```

In app.php:

```
'Session' => [
        'defaults' => 'database',
        'handler' => [
          'engine' => 'DatabaseSession',
          'model' => 'Sessions'
        ],
        'cookie' => 'arbol_login',
        'timeout' => 30,
        'autoRegenerate' => true,
        'ini' => [
            'session.cookie_lifetime' => 1440
        ]
    ],

```

Currently the logout only works for me when the user manually closes the session, but if the session expires, I want it to automatically redirect to the login page. And that is not working.

The session expires, but remains on the page where you are.

---

<div class="post-metadata">

**Author:** ![Zuluru](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/zuluru/32/1230_2.png) [@Zuluru](https://discourse.cakephp.org/u/Zuluru)\
**Post date:** [July 31, 2020, 3:50am UTC](https://discourse.cakephp.org/t/session-expires-automatic-redirection-to-login/8140/5 "2020-07-31T03:50:29Z")

</div>

Is “the page where you are” a page that can be viewed without being logged in?

---

<div class="post-metadata">

**Author:** ![bizdev](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/bizdev/32/1951_2.png) [@bizdev](https://discourse.cakephp.org/u/bizdev)\
**Post date:** [July 31, 2020, 4:35am UTC](https://discourse.cakephp.org/t/session-expires-automatic-redirection-to-login/8140/6 "2020-07-31T04:35:59Z")

</div>

Hi @bichomen,

The option `unauthorizedRedirect` is responsible to redirect unauthorized user to the referrer URL or `loginAction` or ‘/’, as per the [documentation](https://book.cakephp.org/3/en/controllers/components/authentication.html#configuration-options). By default it is `true` so you do not need to specify it to `$this->referer()`, you can remove that and check if it works.

---

<div class="post-metadata">

**Author:** ![bichomen](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/bichomen/32/1070_2.png) [@bichomen](https://discourse.cakephp.org/u/bichomen)\
**Post date:** [August 3, 2020, 6:37pm UTC](https://discourse.cakephp.org/t/session-expires-automatic-redirection-to-login/8140/7 "2020-08-03T18:37:26Z")

</div>

No, if you are on a page that only the user can see and the session expires, while the page is left, it stays there, although you cannot access other pages either.

---

<div class="post-metadata">

**Author:** ![bichomen](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/bichomen/32/1070_2.png) [@bichomen](https://discourse.cakephp.org/u/bichomen)\
**Post date:** [August 3, 2020, 6:38pm UTC](https://discourse.cakephp.org/t/session-expires-automatic-redirection-to-login/8140/8 "2020-08-03T18:38:38Z")

</div>

Yes, you are right about that, but it still doesn’t work.

---

<div class="post-metadata">

**Author:** ![Zuluru](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/zuluru/32/1230_2.png) [@Zuluru](https://discourse.cakephp.org/u/Zuluru)\
**Post date:** [August 3, 2020, 6:53pm UTC](https://discourse.cakephp.org/t/session-expires-automatic-redirection-to-login/8140/9 "2020-08-03T18:53:02Z")

</div>

So, you’re looking for something that actively sends the user _away_ from the page that they are on when their session expires?

---

<div class="post-metadata">

**Author:** ![bichomen](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/bichomen/32/1070_2.png) [@bichomen](https://discourse.cakephp.org/u/bichomen)\
**Post date:** [August 4, 2020, 6:53pm UTC](https://discourse.cakephp.org/t/session-expires-automatic-redirection-to-login/8140/10 "2020-08-04T18:53:27Z")

</div>

Yes, I already have autoregenerate activated, so that when the user browses the session is updated, but if the user does not interact with the page I want one of these options:

- The login page appears
- That when you click on a link, it will take you to the login page
- Or that you get a message advising you that the session has expired.

But no, the current behavior, which does nothing.

---

<div class="post-metadata">

**Author:** ![Zuluru](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/zuluru/32/1230_2.png) [@Zuluru](https://discourse.cakephp.org/u/Zuluru)\
**Post date:** [August 5, 2020, 1:40am UTC](https://discourse.cakephp.org/t/session-expires-automatic-redirection-to-login/8140/11 "2020-08-05T01:40:03Z")

</div>

I think the normal way of doing this would be to have a heartbeat process in JavaScript that makes an Ajax call every X seconds to check the session, and do whatever you want when it comes back as expired.

---

<div class="post-metadata">

**Author:** ![ishan](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/ishan/32/2589_2.png) [@ishan](https://discourse.cakephp.org/u/ishan)\
**Post date:** [August 5, 2020, 10:54am UTC](https://discourse.cakephp.org/t/session-expires-automatic-redirection-to-login/8140/12 "2020-08-05T10:54:41Z")

</div>

For this as @Zuluru suggested you have to use ajax to do this type of work. No server side framework can do this for you by default.

---

<div class="post-metadata">

**Author:** ![bichomen](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/bichomen/32/1070_2.png) [@bichomen](https://discourse.cakephp.org/u/bichomen)\
**Post date:** [August 5, 2020, 5:17pm UTC](https://discourse.cakephp.org/t/session-expires-automatic-redirection-to-login/8140/13 "2020-08-05T17:17:11Z")

</div>

It’s what I imagined, thanks
