WATranslate v4.8.8 — Configurable Admin Automatic Logout

CURRENT VERSION
v4.8.8

NEW SETTING

Settings → Admin session → Automatic logout after inactivity

Available choices:

15 minutes
30 minutes
1 hour
2 hours
4 hours
8 hours
12 hours
24 hours
Never

Default:
1 hour

WHAT COUNTS AS ACTIVITY

Actual admin interaction:
- mouse/pointer clicks
- keyboard input
- touch
- wheel/scroll interaction
- returning focus to the WATranslate window/app

WHAT DOES NOT COUNT AS ACTIVITY

The automatic five-second WATranslate message/contact polling.

This is important: simply leaving WATranslate open does not keep the admin
logged in forever.

SECURITY IMPLEMENTATION

The timeout is enforced in TWO places:

1. Browser/UI timer
   The app immediately returns to the login screen after the configured period.

2. PHP/server session enforcement
   public/api.php independently checks the last genuine admin activity.
   A stale session returns:
   HTTP 401
   error_code: session_expired

This means changing JavaScript in the browser cannot by itself bypass the
server-side inactivity timeout.

MYSQL

The value is stored in the existing wa_settings table:

setting_key:
session_timeout_minutes

Examples:

60    = 1 hour
480   = 8 hours
1440  = 24 hours
0     = Never

No database schema change is required.

FILES TO ADD

src/SecuritySettings.php

FILES TO OVERWRITE

src/AppVersion.php
public/api.php
public/index.php
assets/app.js
public/assets/app.js
assets/branding-v4.5.css
public/assets/branding-v4.5.css
service-worker.js

NO SQL REQUIRED.
NO META CHANGE.
NO WHATSAPP PHONE/TOKEN CHANGE.
NO GOOGLE TRANSLATION CHANGE.
NO WEBHOOK CHANGE.
NO PUSH BACKEND CHANGE.

INSTALL

1. Upload ZIP to:

public_html/whatsapp-server-translator/

2. Extract and overwrite.

3. Desktop:
hard refresh.

4. Mobile/PWA:
fully close and reopen WATranslate.

5. Open:
⋮ → Settings

6. Under:
Admin session

choose the desired automatic logout time.

7. Click:
Save settings

8. Optional MySQL verification:

phpMyAdmin → wa_settings

You should see:

session_timeout_minutes

with the selected number of minutes.

TEST RECOMMENDATION

For a quick functional test choose:
15 minutes

Use the app normally, then leave it untouched. Background polling should
continue temporarily, but after 15 minutes the admin session will be ended and
the login screen will appear.

After testing, choose the preferred normal value, for example 1 hour or 8 hours.
