The absolute lifetime: the limit activity cannot postpone
The second clock is the one most people never learn about, because it only fires on the sessions they keep alive on purpose. It runs from the sign-in and no click can move it.
- signed in
- 09:00
- lifetime
- 12 hours
- ends
- 21:00
- postponable
- no
The absolute lifetime ends a session a fixed period after it was created, regardless of how much activity has happened inside it. On the samples it is 12 hours, so a sign-in at 09:00 is signed out at 21:00 even if the account was clicked a second earlier. It exists so that a session cannot stay open indefinitely.
The clock that activity cannot move
Sample A carries the same sign-in through both clocks. The idle clock is postponable and the absolute one is not, which is the whole difference between them.
| Clock | Starts at | Restarts on activity | Ends at |
|---|---|---|---|
| idle | the last counted action | yes | 10:11 |
| absolute lifetime | the sign-in | no | 21:00 |
| the earlier ending applies | two different starting points | - | 10:11 or 21:00 |
Why a hard ceiling exists
A session is a credential in use, so the two clocks answer two different risks. The idle clock answers an unattended device; the absolute lifetime answers a credential that is being used continuously, deliberately or not, and caps how long a single authenticated interval can exist before the account is re-proved. The practical effect on a reader is narrow and worth knowing: if the account is used for many hours in one sitting, the sign-out will arrive while the screen is in use, at a time that has nothing to do with the last click.
Re-authenticating after it is not a new account and not a change of limits. It is the same account, a new interval, and a fresh set of both clocks - which means the lifetime also resets, and the 12 hours start again from the new sign-in.
- Note the lifetime figure as well as the idle figure; both are usually published and only one is usually read.
- Expect a sign-out during a long session even with constant activity, and expect it at the sign-in time plus the lifetime.
- Treat re-authentication as a new interval: the balance, the bets and the limits are unchanged by it.
- Where a long task depends on the session - an unplaced betslip, a half-filled form - finish it before the lifetime can fire.
- Do not read a mid-use sign-out as a fault or as a security incident; read the two published clocks first.