I am controlling the session of my application with Spring Security, I have two rules to terminate the session, max-session
<session-management>
<concurrency-control max-sessions="1" error-if-maximum-exceeded="true"
expired-url="/publico/login.jsp" />
</session-management>
And it has the timeout
<session-config>
<session-timeout>20</session-timeout>
</session-config>