mirror of
https://github.com/penpot/penpot.git
synced 2026-10-03 09:16:15 +00:00
* ✨ Enforce idle and absolute session expiration Sessions now expire on two server-side conditions: an idle window (PENPOT_AUTH_TOKEN_COOKIE_MAX_AGE, default 7d) and an absolute cap from creation (PENPOT_AUTH_TOKEN_COOKIE_MAX_AGE_ABSOLUTE, default 30d, enforced by the token :exp claim). The daily session-gc task deletes rows that exceed either window, so idle sessions can no longer be replayed and active sessions are not deleted at the idle window. Also remove the legacy v1 HTTP sessions: the http_session table and the string-id / :ver 0 token code paths are gone. Any v1 cookie now requires a fresh login. Document the session expiration configuration in the technical guide and add a backend memory describing the token, renewal and GC model. Closes #11646 AI-assisted-by: deepseek-v4.1-flash * 🐛 Address session-expiration review findings F1-F4 Fix the unreadable test (a stray paren broke whole-suite discovery), enforce idle expiration on every request in wrap-authz, fail boot fast when the absolute cap sits below the idle window, and align config defaults with the memory rule while fixing its migration number and stale reference. Closes #11646 AI-assisted-by: muse-spark-1.3-contributor
Penpot Docs
Penpot documentation website.
Usage
To view this site locally, first set up the environment:
# only if necessary
nvm install
nvm use
pnpm install
And launch a development server:
pnpm start
You can then point a browser to http://localhost:8080.
Tooling
- Eleventy (11ty)
- Diagrams with plantuml. See also real-world-plantuml.
- Diagrams with svgbob and mermaid.
- arc42 template.
- c4model for software architecture, and an implementation in plantuml.