always check resource session length

This commit is contained in:
miloschwartz
2025-10-27 09:45:12 -07:00
parent 9fbea4a380
commit 4cfd1b1ff5

View File

@@ -387,7 +387,6 @@ export async function verifyResourceSession(
if (resourceSession) {
// only run this check if not SSO sesion; SSO session length is checked later
if (!(resourceSessions.userSessionId && sso)) {
const accessPolicy = await enforceResourceSessionLength(
resourceSession,
resourceData.org
@@ -400,7 +399,6 @@ export async function verifyResourceSession(
);
return notAllowed(res, redirectPath, resource.orgId);
}
}
if (pincode && resourceSession.pincodeId) {
logger.debug(