What the standard says
For each time limit that is set by the content, at least one of the following is true:
Why it matters
Reading, typing and switching input methods all take longer for some people. A twenty-minute session limit is a barrier, not a security feature.
What a failure looks like
- failsA checkout that expires silently and loses the basket.
- failsA carousel that advances before the text can be read.
How to fix it
- doWarn before a session expires and offer a one-click extension.
- doLet the user set or remove the limit where the design allows it.
How A11ySignal checks it
1 automated check runs against this criterion on every scan.
criticalmeta-refreshDelayed refresh under 20 hours must not be used