# External Link Time Out

**URL:** <https://pug.phocassoftware.com/t/external-link-time-out/1077>\
**Category:** Product Ideas\
**Created:** [June 12, 2019, 11:07pm UTC](https://pug.phocassoftware.com/t/external-link-time-out/1077 "2019-06-12T23:07:28Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![StuartH](https://sea1.discourse-cdn.com/flex015/user_avatar/pug.phocassoftware.com/stuarth/32/394_2.png) [@StuartH](https://pug.phocassoftware.com/u/StuartH)\
**Post date:** [June 12, 2019, 11:07pm UTC](https://pug.phocassoftware.com/t/external-link-time-out/1077/1 "2019-06-12T23:07:28Z")

</div>

I’m always concerned about external links and the security risk the expose.

I wonder if an option when setting them up to set an expiry date, or more likely an admin setting to force an external link to expire after x days would be possible?

This would mean that while the security risk still applies while the link is active, a member of staff that left months ago can’t get indefinite access to data.

Would be good then for Admin to run a report of external links and the expiry dates and status of a link and in that screen expire or refresh one or multiple links. Refreshing would create a new link.

---

<div class="post-metadata">

**Author:** ![JonKemp](https://sea1.discourse-cdn.com/flex015/user_avatar/pug.phocassoftware.com/jonkemp/32/334_2.png) [@JonKemp](https://pug.phocassoftware.com/u/JonKemp)\
**Post date:** [June 14, 2019, 7:40am UTC](https://pug.phocassoftware.com/t/external-link-time-out/1077/2 "2019-06-14T07:40:43Z")

</div>

Great idea, when we are at the prototype phase we use the URL option to let the senior stakeholders (who are not a Phocas user yet) review how we are doing. We already have had this issue crop up, where a URL has gone un-spotted for a while. An expiry date would be a great way to close this security exposure.

---

<div class="post-metadata">

**Author:** ![Tim.Leonard](https://avatars.discourse-cdn.com/v4/letter/t/8dc957/32.png) [@Tim.Leonard](https://pug.phocassoftware.com/u/Tim.Leonard)\
**Post date:** [June 21, 2019, 3:30pm UTC](https://pug.phocassoftware.com/t/external-link-time-out/1077/3 "2019-06-21T15:30:36Z")

</div>

Thanks both for your suggestion. An expiry was discussed many times during the implementation of this feature, and we ultimately decided to proceed without it. Instead we made it easy to turn off external links, obvious when they are active, and disabled them when something important like relevant restrictions were adjusted.  
Having said that, it is obviously a good suggestion, and it has been logged in our system for potential future inclusion.

Do you see users setting individual expiry dates for each external link? Or a global setting that applies to all external links across the organisation?

---

<div class="post-metadata">

**Author:** ![StuartH](https://sea1.discourse-cdn.com/flex015/user_avatar/pug.phocassoftware.com/stuarth/32/394_2.png) [@StuartH](https://pug.phocassoftware.com/u/StuartH)\
**Post date:** [June 21, 2019, 3:51pm UTC](https://pug.phocassoftware.com/t/external-link-time-out/1077/4 "2019-06-21T15:51:19Z")

</div>

In my view I think it should be an administrator setting where:

a) The administrator can see one list of all links created (can filter for active/expired) and he can terminate them one by one without having to go to the actual source report

b) The expiry date could be set when creating the link, e.g. expire after 7 days, 2 weeks, 1 month or ultimately “No Expiry” - however if the Administrator can set a “Maximum Period” that will restrict what the issuer can set that would be good too.

---

<div class="post-metadata">

**Author:** ![Tim.Leonard](https://avatars.discourse-cdn.com/v4/letter/t/8dc957/32.png) [@Tim.Leonard](https://pug.phocassoftware.com/u/Tim.Leonard)\
**Post date:** [June 24, 2019, 2:09pm UTC](https://pug.phocassoftware.com/t/external-link-time-out/1077/5 "2019-06-24T14:09:15Z")

</div>

OK thanks @StuartH.  
Although there is no expiry at present, the administrator can view all active links and terminate them individually or in bulk.

 ![image](https://us1.discourse-cdn.com/flex015/uploads/phocassoftware/original/1X/32cb0c4071d97227fe13d3819ed02ea93e7d3828.png)

---

<div class="post-metadata">

**Author:** ![StuartH](https://sea1.discourse-cdn.com/flex015/user_avatar/pug.phocassoftware.com/stuarth/32/394_2.png) [@StuartH](https://pug.phocassoftware.com/u/StuartH)\
**Post date:** [June 24, 2019, 3:57pm UTC](https://pug.phocassoftware.com/t/external-link-time-out/1077/6 "2019-06-24T15:57:44Z")

</div>

Aha, thanks Tim
