
Success criterion 2.2.5
Re-authenticating
When an authenticated session expires, the user can continue the activity without loss of data after re-authenticating.
- Level AAA
- Principle 2: Operable
- Guideline 2.2: Enough Time
In a user’s words
“If you log me out every 5 minutes, I swear I'll start writing my passwords on sticky notes!”
What each role can do
- Product manager
- Ensure session timeouts provide a seamless way to re-authenticate without data loss.
- Designer
- Design user-friendly re-authentication processes that retain the user’s previous state.
- Developer
- Implement session management that allows for easy re-authentication without loss of data.
- Tester
- Test to make sure that re-authenticating does not result in the loss of user data or state.
Once it is fixed
“Thank you for saving my work and my sanity. No more password post-its!”
Share this with your team
The quotes are written to illustrate the criterion. They are not testimonials from real people. For the official wording, find 2.2.5 in the W3C quick reference for WCAG 2.2 (opens in a new tab).
Or press ←the left arrow and →the right arrow.