legacy-knowledge-base
公開されました Sep. 10, 2025

Activity within embedded pages does not maintain user sessions

written-by

Justin Mann

How To articles are not official guidelines or officially supported documentation. They are community-contributed content and may not always reflect the latest updates to Liferay DXP. We welcome your feedback to improve How To articles!

While we make every effort to ensure this Knowledge Base is accurate, it may not always reflect the most recent updates or official guidelines.We appreciate your understanding and encourage you to reach out with any feedback or concerns.

legacy-article

learn-legacy-article-disclaimer-text

Issue

  • Activity within an application found on a Liferay embedded page does not count as activity with regard to a Liferay session, so it does not maintain the user session.
  • As a result, the user is session expires after the appropriate timeout period

 

Environment

  • Quarterly Release
  • Liferay DXP 7.4

 

Resolution

  • The iframes are isolated from the page on which they are placed. This is the intended design of how they should work.
  • Because of this, actions inside the iframe (i.e. embedded on the page) won't extend the session of the broader page that the iframe is placed on
  • The reason this behavior is intended is that modifying this configuration can lead to CSRF security problems.
did-this-article-resolve-your-issue

legacy-knowledge-base