Coming from the Citrix world, unless there is something I am missing, we need a way for the logon page to expire without killing the html5 session. If we are lucky, the "user" is typically going to log out of their application or desktop session, but it is highly likely that they will walk away from the logon page. This page should expire after X amount of time so that if someone is using a public kiosk (like at a hotel lobby) and they walk away, a stranger does not have access to our systems. Has anyone else thought of this issue?