Version 0.89.0
2026-08-22 10:45:29 UTC
Changed
1A session now ends 30 days after it was created, however recently it was used.
A session expires 24 hours after it was last used, and that 24 hours moved forward on every request you made, so a session that kept being used had no end at all. From now a session that is more than 30 days old ends on its next request. A device where you ticked “Remember this device” shows the sign-in screen once and then signs itself back in from the stored code (it asks for your passphrase first if you set one); a device where you did not will ask for your account code again. What this closes is one stolen access token being usable forever — it does not stop a token from being taken in the first place.