No Code Attached Yet a11y a11y-audit-backlog a11y-priority-serious (High)
avatar mbeganyi-a11y
mbeganyi-a11y
8 Sep 2026

Steps to reproduce the issue

NOTE: Accessibility backlog issue and work-in-progress. This issue has been opened to account for all the issues flagged in the initial Milestone 1a Audit Report. If this is a duplicate issue, it will be closed by the end of September 2026.

Milestone 1a finding ID M1a-004
Backlog priority High
Severity — carried from Milestone 1a Serious
Implementation effort Medium
Target milestone(s) MS2a, MS3a, MS3b, MS7a, MS7b, MS7c, MS8a, MS9a, MS10
WCAG 2.2 success criterion 2.2.1 Timing Adjustable
Responsibility tag(s) from report Design, Development
Affected Joomla area/component https://accessibility-project.joomla.org/results/Milestone-1a/milestone1/deliverable1/wcag-report#c81fc029-4b10-400e-86a1-ccb8814587ee
Affected user journey(s) 01 – Backend Template (Atum); 05 – MFA Setup - Method / Methods Views; 06 – Media Manager (com_media); 07 – Installer Wizard (com_installer/Install); 08 – Backend List View Pattern; 09 – Backend Edit Form Pattern; 11 – Backend Options including Permissions; 12 – Update Joomla
Source report/reference Milestone 1a WCAG audit report
STF reporting reference To be assigned
Issue owner To be assigned
Status Triage

Audit finding

User session expires without warning

User impact

Users who need more time may lose progress or be unable to complete the task before the time limit expires.

Remediation plan

Implement a component-level and template-level fix that allows for session expiry limit to be extended or dismiss the expiry and continue.

Steps to reproduce

1. Open an area of Joomla that requires logging in.

2. Note the session timeout behaviour by idling the session for 15 minutes.

3. Wait until the warning or timeout occurs.

4. Attempt to extend the session and continue the task.

5. Observe that the user is automatically signed out without warning.

Version

6.1

Expected result

Users can do one of the following actions:

  • Turn off: The user is allowed to turn off the time limit before encountering it; or
  • Adjust: The user is allowed to adjust the time limit before encountering it over a wide range that is at least ten times the length of the default setting; or
  • Extend: The user is warned before time expires and given at least 20 seconds to extend the time limit with a simple action (for example, "press the space bar"), and the user is allowed to extend the time limit at least ten times.

Alternatively, extend the session timeout to over 20 hours.

Actual result

User is automatically logged out after an idle period of 15 minutes.

What device were you using? (eg, phone, laptop)

Desktop web

What web browser were you using? (eg, Chrome, Safari)

Chrome, Firefox, Edge, Safari

Assistive Technology?

N/A

Additional Comments

No response

avatar mbeganyi-a11y mbeganyi-a11y - open - 8 Sep 2026
avatar mbeganyi-a11y mbeganyi-a11y - change - 8 Sep 2026
Labels Added: a11y a11y-audit-backlog a11y-priority-serious (High)
avatar mbeganyi-a11y mbeganyi-a11y - labeled - 8 Sep 2026
avatar joomla-cms-bot joomla-cms-bot - change - 8 Sep 2026
Labels Added: No Code Attached Yet
avatar joomla-cms-bot joomla-cms-bot - labeled - 8 Sep 2026
avatar brianteeman
brianteeman - comment - 8 Sep 2026

Again not 100% true

Any page that has user interaction has behaviour.keepalive

avatar mbeganyi-a11y
mbeganyi-a11y - comment - 9 Sep 2026

I'll need to investigate this also as users can set timeouts in global settings.

avatar mbeganyi-a11y mbeganyi-a11y - change - 9 Sep 2026
Title
User session time limit causes involuntarily logout
Atum / Cassiopeia: User session time limit causes involuntarily logout
avatar mbeganyi-a11y mbeganyi-a11y - edited - 9 Sep 2026

Add a Comment

Login with GitHub to post a comment