Login - Don't Log Me Out/Extend Log Out Time (more than 60 minutes)
Develop the feature where Xero doesn't log user out time is extended for more than 60 minutes when it’s idle.
Purpose: Because having to log in again can disrupt users' workflow, which some users had to be interrupted as they’re also taking care of their business at the same time.
Hi everyone, we appreciate the interest surrounding this idea, however we want to be open that we're unable to extend our log-out time past 60 minutes. Xero hold a lot of sensitive information including bank data and we're required to be as secure as online banking.
Any session information running on a web browser can potentially be stolen. If the session does not time out. You then have an infinitely long vulnerability window to session hijacking. Our best option is to keep a tight expiration window on the session cookie, and regenerate them frequently. Even setting a long timeout doesn't help with this - too long a timeout will greatly increase the risk of invasion or potentially jeopardise your personal data and the safety and integrity of the Xero application itself. This is why we maintain control of this.
If we detect there's been no activity on a page (e.g move movements, clicks, keyboard) for 10 minutes you'll receive an inactivity prompt ('Hey Kelly, are you still there?') and if your session reaches 60 minutes you'll be redirected to the login page.
- As a suggestion you can periodically refresh the screen <F5> to prevent the security timeout kicking in.
In more recent comments here it sounds like some of you are having issues with the login process or staying logged into Xero for less than 60 minutes. If you're experiencing unexpected behaviour, we'd highly recommend raising a case with our team of specialists at Xero Support where we have tools to investigate and confirm what's going on - Any details you can provide the team on the page you're trying to sign in from (e.g URL, error 500 received) or actions you were making when the login issue occurred will help. Thanks
-
Jan Sovak
commented
Relly Xero, how this could be beautiful accounting when I lose 3 minutes every day a few times waiting to get signed in. Please provide us with Google Auth. or something similar, or let us whitelist some IP addresses from where this will not be necessary to do every 60 minutes or so. And give us some feedback on this as there were no responses from the Xero team on this for quite some time.
-
Clare Dingle
commented
Adjusting the time-out would be absolutely wonderful - it is so disruptive to be logging in so frequently.
Looking at this request, it seems users have been asking for this for almost 10 years. Why is Xero so slow to respond?
-
Simon Leaity
commented
Seriously Xero this is nearly 10yrs old, it is fustrating and slow
-
Vicki Brookes
commented
Yes please. At lease give options to this extremely annoying feature. So annoying all day to be doing this. Come on please asap
-
Elizabeth Nuss
commented
It's not unusual to allow the account holder/administrator to personalise the time before the software logs company users out.
Surely we can all be responsible for managing the risk in Xero according to our company needs.
-
David Baker
commented
As with not being able to post a payment under bills to pay unless in home currency this issue also seems ot have been around for such a long time. So many people work from home on their own, and it really does not make sense to not enable them to etend this time. Xero is losing rapidly its reputation as responsive to its users needs when compared to other cloud based accounting packages not only amongst users but also accountants who promote to their clients.
-
Jo Murray
commented
I use the Xero projects and tasks feature along with the Xero timer to log my time while working. I use this timer/tasks all day every day. It's so tedious with the system constantly logging me throughout the day. What's the point of a project timer if I can't use it effectively?
-
Rachael Hardacre
commented
Please fix this.
-
Gretel O'Malley
commented
Working on something and go to lunch, come back and have to reset a dozen reports from scratch... so often
-
Tony White
commented
OMG!!!! CAN I VOTE FOR THIS TO CHANGE 40 OR MORE TIMES............ soooooo over having to log in again and again and again and again and again and again and again (get the message😡) Please fix this..........
-
Dayle O'Callaghan
commented
Thanks Matt Eady & Kevin Y :)
HEY XERO, if a work around is required, isn't it about time you did something instead of messing with screen views ?
-
Ariana Klitzner
commented
Especially with project tracking it is really frustrating to try to go from task to task, track accurately, and then have to sign in
-
Wendy Jones
commented
Great to know there is work around for this issue - thanks Kevin Y. However Xero I think you should review the user comments as in my mind it is your issue to rectify.
-
Tasman Simkins
commented
Thanks for the tip Kenin Y. I will try that.
-
Kevin Y
commented
Hi Tasman,
I have had that issue in the past too! I resolved it by opening another tab and logging in with the new tag, once logged in your original tab should be ok with saving the new changes without losing everything.
Can vouch for Mat Eady's rec of Tab Reloader (or similar) from chrome store to prevent time out issues. Have more than one tab of Xero open and pin one of the tabs as the one to be reloaded at set intervals. Set and forget.
-
Tasman Simkins
commented
This is very frustrating and causes me a lot of lot work. I have an invoice open for working on. I leave it for a bit and come back to it make a lot of changes and then when I try and save it come up that it cannot save. Instead of just loggin back in and allowing me to save the invoice I loiose all of the changes that i have made. It is so frustrating and should not be the case. Xero Fix it,.
-
Suzanne Varghese
commented
Having to continually log back is inefficient, inconvenient and therefore costly and frustrating. Is there a solution to this problem yet?
-
Suzanne Varghese
commented
How annoying is this
-
Administrator ToTal Risk
commented
This is probably the only frustration I have with Xero and I am reminded of it multiple times each day. As for 'periodically refreshing the screen' as a workaround - Kafkaesque
-
Matthew Dipple
commented
It would be great to be able to disable the timeout function on a trusted computer as well--I work on a computer in a secure location all day, and track time using the Xero timer. It is a pain to need to log in 10+ times per day just to track time! Please add my enthusiastic vote for this item.