Prevent data loss from session timeouts

SkillSecurity

session-timeout-recovery is a skill for reviewing authenticated user flows and long forms. It checks how sessions behave when they expire, covering warning timing, dialog accessibility, autosave frequency, timeout extension, and post-login state restoration on both the client and server side.

Use Prevent data loss from session timeouts in Claude, ChatGPT or Ahel Desktop

Free. Sign in, add Prevent data loss from session timeouts and connect your AI. About a minute.

Also: Claude Code · Cursor · Codex

Then ask your AI: use the Prevent data loss from session timeouts skill

Details

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Have an AI agent with the ability to load skills.

Prevent data loss from session timeoutsStart free

What your AI can do with it

  • Check warning timing before a session expires
  • Review timeout dialog accessibility
  • Assess autosave frequency in long forms
  • Verify timeout extension behavior
  • Check post-login state restoration after re-login
  • Review both client and server behavior in authenticated flows

Getting started

  1. Have an AI agent with the ability to load skills.
  2. Add the session-timeout-recovery skill to the agent's available skills.
  3. Ask the agent to review an authenticated user flow or long form; the skill applies when checking warnings, autosave, timeouts, and post-login state restoration.

What this skill tells your AI

The instructions your AI receives, as published by thedaviddias/front-end-checklist in skills/session-timeout-recovery/SKILL.md and read by ahel’s review.

Users with cognitive, motor, or vision disabilities may need longer to finish forms and authenticated tasks. Silent session expiry can erase work, force a restart, and block completion of important transactions.

Quick Reference

  • Warn users before a timeout causes lost work
  • Allow time extension for content-controlled time limits when feasible
  • Autosave or preserve entered data across logout and re-authentication
  • Keep timeout dialogs keyboard accessible and announced to assistive technology

Check

Review authenticated flows, forms, and long-running tasks for inactivity timeouts. Verify users are told the timeout duration, warned before expiry, can extend the session when allowed, and can resume after re-authenticating without losing work.

Fix

Add an accessible timeout warning, preserve drafts or submitted data across session expiry, and restore the user to the same step after re-authentication. Where the time limit is content-controlled, offer turn off, adjust, or extend behavior when feasible.

Explain

Explain how timeout warnings, extension controls, autosave, and re-authentication recovery reduce data loss and align with WCAG enough-time guidance.

Code Review

Review authenticated forms, checkout flows, editors, and long-running tasks related to Prevent data loss from session timeouts. Flag routes or components that can expire silently, discard entered data, or block recovery after re-authentication.


For full implementation details, code examples, and framework-specific guidance, see references/rule.md.

Rule page: https://frontendchecklist.io/en/rules/accessibility/session-timeout-recovery

Signals

GitHub stars
74k
Forks
7k
Last commit
Oct 2026

Questions

When should this skill be used?
Use it when reviewing authenticated user flows or long forms, where session expiry can interrupt a user's work.
What does it check?
It checks warning timing, dialog accessibility, autosave frequency, timeout extension, and post-login state restoration.
Does it cover both client and server behavior?
Yes, it checks both client and server behavior for session timeout handling.
Advanced
Item type
skill
Key
session-timeout-recovery
Source
github.com/thedaviddias/front-end-checklist