Prevent data loss from session timeouts

SkillSecurity

session-timeout-recovery is a skill for AI agents that reviews authenticated user flows and long forms for session timeout problems. It checks both client and server behavior so that users who need more time do not silently lose entered work. It covers warning timing, dialog accessibility, autosave, timeout extension, and post-login state restoration.

Available today. Use it from your connected AI after setup.

1. Have an agent that can load skills and access the code or flows to review.

Then ask your AI: use the Prevent data loss from session timeouts skill

What your AI can do with it

  • Review authenticated flows and long forms for inactivity timeouts
  • Verify users are told the timeout duration and warned before expiry
  • Check that timeout dialogs are keyboard accessible and announced to assistive technology
  • Assess autosave frequency and data preservation across logout and re-authentication
  • Flag routes or components that expire silently or discard entered data
  • Explain how fixes align with WCAG enough-time guidance

Getting started

  1. 1. Have an agent that can load skills and access the code or flows to review.
  2. 2. Add the session-timeout-recovery skill to the agent's available skills.
  3. 3. Ask the agent to review an authenticated flow, form, or long-running task with the skill.
  4. 4. Use the flagged issues to add accessible timeout warnings, autosave, and post-login state restoration.
  5. 5. Consult references/rule.md for implementation details and framework-specific guidance.

What this skill tells your AI

The instructions your AI receives, as published by thedaviddias/front-end-checklist in skills/session-timeout-recovery/SKILL.md and read by ahel’s review.

Users with cognitive, motor, or vision disabilities may need longer to finish forms and authenticated tasks. Silent session expiry can erase work, force a restart, and block completion of important transactions.

Quick Reference

  • Warn users before a timeout causes lost work
  • Allow time extension for content-controlled time limits when feasible
  • Autosave or preserve entered data across logout and re-authentication
  • Keep timeout dialogs keyboard accessible and announced to assistive technology

Check

Review authenticated flows, forms, and long-running tasks for inactivity timeouts. Verify users are told the timeout duration, warned before expiry, can extend the session when allowed, and can resume after re-authenticating without losing work.

Fix

Add an accessible timeout warning, preserve drafts or submitted data across session expiry, and restore the user to the same step after re-authentication. Where the time limit is content-controlled, offer turn off, adjust, or extend behavior when feasible.

Explain

Explain how timeout warnings, extension controls, autosave, and re-authentication recovery reduce data loss and align with WCAG enough-time guidance.

Code Review

Review authenticated forms, checkout flows, editors, and long-running tasks related to Prevent data loss from session timeouts. Flag routes or components that can expire silently, discard entered data, or block recovery after re-authentication.


For full implementation details, code examples, and framework-specific guidance, see references/rule.md.

Rule page: https://frontendchecklist.io/en/rules/accessibility/session-timeout-recovery

Signals

GitHub stars
74k
Forks
7k
Last commit
Aug 2026

Questions

When should this skill be used?
Use it when reviewing authenticated user flows or long forms, where a silent session timeout could erase work or block completion of a task.
What does it check?
Both client and server behavior: warning timing, dialog accessibility, autosave frequency, timeout extension, and post-login state restoration.
Who benefits from these checks?
Users with cognitive, motor, or vision disabilities who may need longer to finish forms and authenticated tasks, and who risk losing work on silent expiry.
Advanced
Item type
skill
Key
session-timeout-recovery
Source
github.com/thedaviddias/front-end-checklist