Requested Enhancement:
Provide a configurable pre-login challenge/token timeout.
Alternatively, automatically refresh or renew the challenge/token while the login page remains open.
Allow administrators to define an appropriate timeout based on operational requirements and security policies
Details :
Currently, the Perspective pre-login authentication challenge/token has a hardcoded ~5-~15 Min timeout that cannot be configured. Once the login page remains idle beyond this timeout, users can enter valid credentials but receive an HTTP 400 error on the /next-challenge request. The user must manually refresh the login page before authentication can proceed successfully.
This behavior has been reproduced in both web browsers and Perspective Workstation and has been confirmed as the current expected product behavior.
Additional Notes:
This functionality should be independent of the existing Perspective Session Inactivity Timeout setting.
Increasing the session inactivity timeout does not prevent the pre-login challenge from expiring.
The current behavior can lead to failed login attempts and user confusion when login screens remain open for extended periods before authentication.