This topic is regarding sessions in the WSO2 Identity Server (IS) and the process of enabling session persistence for these sessions. This is particularly useful when the remember me option is selected when logging into either the service provider or the WSO2 Identity Server.
Understanding sessions in the WSO2 Identity Server
When you log in to the Web application using WSO2 Identity Server, a single sign-on (SSO) session is created by the Identity Server for the user of the application. Also, as the user logs in to the Web application, there is session created in the Web application itself for the user. These are two separate sessions and they are not synchronized with each other.
For an example, if the Web application has a session timeout of 20 minutes and the WSO2 IS SSO session timeout is 5 minutes, the application users will not see the login page up to 20 minutes. That is because WSO2 IS is not invalidating the session by force on the Web application.
If the Web application session timeout is 5 minutes and the WSO2 IS SSO session timeout is 20 minutes, the users will not see the login page up to 20 minutes. This is because even when the Web application container session timeout after 5 minutes, the session was kept alive since WSO2 IS SSO session is still alive. The user will not be redirected to the login screen of the SP until the WSO2 IS SSO session is invalidated.
WSO2 Identity Server creates separate SSO session for SSO login and it is different from the session that is created when you log in to the Identity Server management console.
When end user logs in through the WSO2 Identity Server for the service provider application (using SAML2 SSO, OpenID Connect, Passive STS, etc.), the Identity Server creates a SSO session for end users and a cookie that is related to the created SSO session is set to the user’s browser.
This cookie can be seen as commonauthId. It is set to the user’s browser with the hostname of WSO2 Identity Server instance and the value of the commonauthId cookie is the SSO session identifier. When SSO session is created in the WSO2 Identity Server, the session is put into the session cache and persisted to the database. To persist it in to the database, you must enable the session persistence.
SSO sessions have been stored in a in-memory cache. It is recommended to persist the SSO session due to following reasons.
- If you are running a single WSO2 Identity Server instance and the server is restarted, all SSO session would be removed. If you have multiple nodes of WSO2 instances, It is not guaranteed that you can recover all the sessions. Although the cache is distributed, it is not 100% split to each node.
- Cache has a limit. If there are large number of SSO sessions, memory can be high and server performance may reduce. So usually the cache is evicted after a given number of entries (by default 10000 entries). Therefore, some SSO session can be evicted from caches when there are large number of user logins.
- When there is a clustered development, if you have no persistence, you need to rely completely on the distributed cache. However, if you have persistence, you can rely on it as well. This increases the reliability of the overall system.
The following configuration found in the
<IS_HOME>/repository/conf/identity/identity.xml file, under the the
JDBCPersistenceManager elements is used to enable session persistence.
The following table describes the elements of the configurations mentioned above.
This enables the persistence of session data. Therefore, this must be configured to
Setting this to
|PoolSize||To improve performance, OAuth2 access tokens are persisted asynchronously in the database using a thread pool. |
This value refers to the number of threads in that thread pool.
This section of the configuration is related to the cleaning up of session data.
|Selecting true here enables the cleanup task and ensures that it starts running.|
This is the timeout value (in minutes) of the session data that is removed by the cleanup task. The default value is 2 weeks.
This is the time period (in minutes) that the cleanup task would run. The default value is 1 day.
|OperationDataCleanUp||This section of the configuration is related to the cleaning up of operation data.|
Note: To work with Single Sign-On you must have session persistence enabled.