Log In Every Time I Close Browser

lunchboxtheman

New Member
Sep 25, 2024
3
0
1
Devoted Community Members,

I have to re-login to the proxmox UI every time I close and reopen my browser. It's not a huge deal but I'm wondering if there's a way to stay logged in across browser sessions. I searched and didn't find much about this issue. Is this expected behavior?

- ONLY happens when I close the browser and re-open. Closing the tab and re-opening a tab without closing the browser I stay logged in
- I do stay logged in to other sites just fine (gmail, adguard home, etc)
- Browsers do not have any auto-clear cookies on close configured. No ad blockers, no nothing. (disabled all of this for testing)
- PVE 8.2.7
- Happens even with fresh install
- Using PAM with TOTP
- Same behavior in Chrome and Firefox
- Same behavior whether I access GUI from IP_Address:8006 or via nginx proxy (I have SSL set up too)
- Same behavior when I disable nginx altogether (fresh install as I said)
- Same behavior when I use a different PAM user other than root with no TOTP


Thank you!
 
Last edited:
This is the normal behavior and there currently is no feature that I'm aware of to stay logged in between browser sessions.

The session expires whenever the session is dropped, i.e. when the browser is closed. This happens on the client side, so even though I won't advise this, if your browser has an option to forcefully save those cookies between sessions, you could stay logged in when exiting and reopening the browser. However, this will only work if the browser is reopened in around two hours as the session will be invalid at around that time.

If you really want to have this feature, you could open a bug request [0], but as I found there were two similar requests [1] and [2] (in the other direction - having timeouts) that have been left undecided for some time now.

[0] https://bugzilla.proxmox.com/enter_bug.cgi
[1] https://bugzilla.proxmox.com/show_bug.cgi?id=1310
[2] https://bugzilla.proxmox.com/show_bug.cgi?id=3575
 
Thanks for the reply. I get it from a security standpoint. (although, I would never leave my computer unlocked and walk away from my desk in an office like one of those linked threads mentioned).

I'd think both ways could be supported anyway with a "keep me logged in" checkbox or something. I only have experience with OAuth where refresh tokens are a thing. No idea what PVE is using but it's probably more work than it's worth compared to other features.

Thanks again.
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!