Unfortunatly I have confirmed the problem with permisions after time-out.
How to reproduce issue:
1. Create tersus application with custom user authentication
2. Create system with requiredPermissions property set.
3. Create view with button that executs somethig (like open dialog or display alert)
4. Create user that is authorized to access system created in point 2.
5. Login to your application
6. Wait till time-out will occure
7. Try execute button:
Expected behavior: button wil not be executed, aplication is reloaded.
Real behavior: user can execute button (if in your button you use 'Tersus/Security/Get Logged-in User' it will return null. This is reason why my users reported more priviliges - some data access was moedeled based on user's login.)
Would it be work aroud to set <session-timeout> to 0 ?
regards, pawel bahyrycz
For best results, use the Firefox browser..