A marketing guy came to me with a request to time out the session every 6 hours regardless of the user activity on the site.
I understand that if the user leaves his computer for a certain period of time (Set right now to 30 minutes) the session should time out, but forcing a user to log in after a certain period of time just doesn't make sense to me
His reason is that if a person is logged in for 6h on the site, it is most likely a bot.
Is this a valid request ?
-ken