Drupal is a registered trademark of Dries Buytaert
Search API Solr 4.4.0 Minor update available for module search_api_solr (4.4.0). Page Manager 8.x-4.0 Major update available for module page_manager (8.x-4.0). Trash 3.1.0-beta2 New beta version released for module trash (3.1.0-beta2). Commerce AutoSKU 3.0.1 Minor update available for module commerce_autosku (3.0.1). Custom Field 4.0.10 Minor update available for module custom_field (4.0.10). Alternative login ID & display names 2.0.12 Minor update available for module alt_login (2.0.12). EntityReference UUID 3.0.1 Minor update available for module entity_reference_uuid (3.0.1). LocalGov Publications Importer 1.1.1 Minor update available for module localgov_publications_importer (1.1.1). Configuration Override Warn 8.x-1.6 Module config_override_warn updated after 10 months of inactivity (8.x-1.6). Table Alternate Rows Module table_altrow crossed 1,000 active installs.

This module prevents users from being logged out of Drupal prematurely when they have an active single sign-on (SSO) session. It integrates with existing autologout settings to ensure users remain logged in as long as their SSO session is valid, improving the experience in multi-site SSO environments.

Makes the contributed Autologout module aware of a federated SSO session. On each authenticated request it asks the SSO Connector Cookie service to cryptographically validate the shared SSO cookie; only then does it refresh Autologout's idle-activity marker. A user who is active elsewhere in the SSO network is therefore not logged out here, while idle and maximum-lifetime timeouts remain genuinely enforced.

Features

  • Refreshes the Autologout idle timer only while a cryptographically valid SSO cookie is present — a merely present or forged cookie never extends the session.
  • Runs before the contributed Autologout subscriber.
  • Falls back to the contributed timeouts unchanged when the cookie submodule is absent.
  • Idle and absolute maximum-lifetime timeout enforcement.
  • Optional signed, cross-site activity cookie (HMAC-verified) to share recent activity across the network.
  • Open-redirect-guarded logout destination, validated both at runtime and at save time.

Requirements

Installation

composer require drupal/sso_connector_autologout
drush en sso_connector_autologout

Part of the SSO Connector bundle

Requires SSO Connector (core) and the contributed Autologout module. See the core project for the full suite.

Activity

Total releases
3
First release
Apr 2026
Latest release
1 week ago
Releases (12 mo)
3 ▲ from 0
Maintenance
Active

Release Timeline

Releases

Version Type Release date
1.0.1 Stable Jul 21, 2026
1.0.0 Stable Jul 18, 2026
1.0.0-beta1 Pre-release Apr 26, 2026