0, 'path' => $repo_name, 'domain' => '', 'secure' => $is_https, 'httponly' => true, 'samesite' => 'Lax', ]); session_start(); // Idle timeout: a signed-in session untouched for SESSION_IDLE_SECONDS is // cleared here, so pages redirect to the login form and API engines answer // 401 (db_auth.php) exactly as for a visitor who never signed in. if (!empty($_SESSION['login_company_id'])) { $last = (int)($_SESSION['_last_activity'] ?? 0); if ($last > 0 && (time() - $last) > SESSION_IDLE_SECONDS) { $_SESSION = []; session_regenerate_id(true); $_SESSION['_idle_expired'] = true; } else { $_SESSION['_last_activity'] = time(); } } } /** * End the current session completely: server data, the session file and the * browser cookie. Used by logout and by any flow that must force a new sign-in. */ if (!function_exists('session_end_completely')) { function session_end_completely(): void { if (session_status() !== PHP_SESSION_ACTIVE) return; $_SESSION = []; $p = session_get_cookie_params(); setcookie(session_name(), '', [ 'expires' => time() - 42000, 'path' => $p['path'], 'domain' => $p['domain'], 'secure' => $p['secure'], 'httponly' => $p['httponly'], 'samesite' => $p['samesite'] ?? 'Lax', ]); session_destroy(); } }