Shared accounts and forgotten sessions on a second machine are two of the commonest findings in an access review. Single-session mode answers both: when a user signs in, every other session they hold ends, on every node of the cluster.
From a flag to a company setting
- Set per company The mode is a company-level setting in the configuration database, replacing the Java system flag it started as.
- Cluster-wide over Redis A login publishes an event naming the user and the node. Every other node subscribes and invalidates that user's sessions; sessions on the same node are invalidated directly.
- Designed twice A first implementation flagged rows in the shared session table and scanned them. The published-event design replaced it, with no polling.
Documented
- One overview of login Form login, LDAP, OAuth and OpenID Connect, SAML 2.0 with single logout, and session management are described in a single 1,200-line document.
The setting is off by default. Where a regulator or an internal policy requires one active session per person, it is one row to change.