# Session timeout for specific users

**URL:** <https://discourse.cakephp.org/t/session-timeout-for-specific-users/10662>\
**Category:** Need Help\
**Created:** [October 6, 2022, 5:35pm UTC](https://discourse.cakephp.org/t/session-timeout-for-specific-users/10662 "2022-10-06T17:35:21Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![shadowx.jb](https://avatars.discourse-cdn.com/v4/letter/s/a88e4f/32.png) [@shadowx.jb](https://discourse.cakephp.org/u/shadowx.jb)\
**Post date:** [October 6, 2022, 5:35pm UTC](https://discourse.cakephp.org/t/session-timeout-for-specific-users/10662/1 "2022-10-06T17:35:22Z")

</div>

I use `cakephp/authentication` for user login, can it be set for a certain user `id=1` so that the session timeout is 1 week?

In the `config/app.php` file, I have set the session as follows

```auto
'Session' => [
    'defaults' => 'cake',
    'timeout' => 24 * 60, // 1 day
],

```

Thanky you

---

<div class="post-metadata">

**Author:** ![KevinPfeifer](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/kevinpfeifer/32/3365_2.png) [@KevinPfeifer](https://discourse.cakephp.org/u/KevinPfeifer)\
**Post date:** [October 7, 2022, 12:48pm UTC](https://discourse.cakephp.org/t/session-timeout-for-specific-users/10662/2 "2022-10-07T12:48:46Z")

</div>

You could extend the default `SessionAuthenticator`, overwrite the `persistIdentity` method and set that new custom SessionAuthenticator inside your AuthenticationService.  
Inside `persistIdentity` the session is actually checked and re-written.  
So you could set the Session timeout config before the session is set/renewed for your specific identity.
