Login session
ioki Platform uses sessions. This means that when an administrator logs in to Control Center, a login session and a corresponding session ID (that is, an access token) are created.
After 20 failed sign-in attempts, an administrator is locked out. They receive an email to unlock the account. If the email is not sent automatically, it can be requested manually at any time on the login screen. In addition, another authorized administrator can unlock the user.
On the client side, two encrypted and signed cookies are set. These contain the corresponding access token:
The ioki Platform session cookie (
_triebwerk_session): This cookie is stored and expires after 60 minutes without activity, or if all current sessions are manually destroyed by the administrator in Control Center. If the Remember admin token was set and is still available when the standard 60-minute timeout is reached, the session cookie is reissued by the server after receiving the valid remember admin token. Technically, this creates a new session with a new token, but the administrator does not need to enter their credentials again.Remember admin token (
remember_admin_token): If the administrator selects the Remember me checkbox on sign-in, this token is set. It expires after two weeks or after the administrator logs out manually.
These cookies are secure and transferred only via HTTPS. They are used only for authentication and can be accessed only by ioki Platform. They cannot be accessed via JavaScript, because the Set-Cookie header uses the Secure and HttpOnly attributes.
In ioki Platform, this is implemented with the devise gem.
For viewing and ending your own sessions in the UI, see Account settings.