Skip to contentSkip to content
EDUBaseCloud
Guide

Login & Access: Why You Get Logged Out

School software signs you out automatically because your session has expired — a security measure so an unattended login cannot be reused; "page expired" means a form was submitted after its security token lapsed. In EDUBase Cloud, staff sessions expire, so sign in again with your institute code and username and re-submit the screen.

What does "session expired" actually mean?

When you sign in to any web portal, the server issues your browser a session — a temporary pass that says "this person has already proved who they are". That pass is intentionally short-lived. If it never expired, a login left open on a shared front-desk PC, or a laptop that walked out of the building, would stay usable indefinitely.

EDUBase Cloud staff sessions expire. Once that happens, the next click is bounced back to the login page. Nothing you had already saved is lost — saved records are on the server. What is lost is anything typed into a form and not yet saved.

This is standard for finance-grade software. A fee counter screen with rights to record payments, approve discounts or change salary plans is exactly the screen you do not want left open and signed in.

  • Session expiry protects records you have rights to change, not just your own profile
  • Saved data is never affected; only unsaved form input is lost
  • Re-signing in with the institute code, username and password restores you to the same rights and campus scope

Why does the portal say "page expired" instead of logging me out?

"Page expired" is a slightly different event. Most modern web applications attach a one-time security token to every form so that a third-party site cannot trick your browser into submitting it — the general protection is called CSRF (cross-site request forgery). If the page sat open long enough for that token to lapse, the server rejects the submission and shows a page-expired message.

In practice this happens when a challan form, an admission form or a marks entry screen has been open for a long stretch — a lunch break, an overnight tab, a browser restored from a previous day. The remedy is the same every time: reload the screen so a fresh token is issued, sign in if asked, and enter the data again.

It is worth warning fee office and exam staff about this habit specifically, because those are the screens most often left open with a lot of typed-in work on them.

  • Reload the page rather than pressing back and re-submitting
  • Do not keep entry screens open across days; open them when you are ready to work
  • For long tasks such as marks entry, save in batches rather than at the very end

Which everyday causes have nothing to do with the software?

Before treating repeated logouts as a fault, rule out the ordinary causes first. Most of them sit on the device or the network, not on the server.

Shared computers are the biggest source of confusion in school offices. If two staff members use the same browser profile and one signs in with a different account, the other is pushed out. Give each staff member their own login — EDUBase allows unlimited staff logins with per-user, per-screen and per-action rights and campus scope — and, where possible, their own Windows or browser profile.

Browsers that clear cookies on close, private/incognito windows, aggressive "cleaner" utilities and clock settings that are badly out of date will all break sessions. So will an unstable internet connection, which can make a perfectly valid session look dead mid-save.

  • Two people sharing one browser profile signing in to different accounts
  • Incognito or private windows, which discard the session when closed
  • Browser or third-party cleaner software set to clear cookies and site data
  • Device date and time significantly wrong
  • Patchy connectivity at the moment a form is submitted
  • An old tab restored from a previous session still holding a stale token

How should an admin check access problems before raising a request?

Work through the simple checks in order; most access complaints are resolved in the first three.

If a staff member says they cannot get in at all, rather than being logged out mid-work, the issue is usually the credentials themselves. Staff sign in with the school's institute code plus their username and password, and staff passwords are reset by an admin from the portal — nobody should be circulating a shared password. Parents are different: they log in to the Parents App with a rotating one-time code sent to the registered mobile, and the Parent App OTP Portal lets staff look up or issue that code when the SMS has not arrived.

If you need to see whether something actually changed, User Logging records who created, changed or deleted what, with the record opened and the change highlighted, and a daily summary reaches the owner.

  • Confirm the institute code, username and spelling of the password
  • Have the user close every tab, open one fresh tab and sign in again
  • Check whether the person is on a shared device with somebody else's session
  • Confirm the user's privileges and campus scope actually include the screen they want
  • For parents, check the OTP portal and the registered mobile number
  • Ask the in-app AI assistant, which answers how-to questions in English or Roman Urdu with links to the exact screen and tutorial video

What can the school do to reduce interruptions?

Session expiry is not something to switch off; it is the control that makes it safe to give a fee clerk or an HR officer real rights. What you can do is reduce how often it interrupts real work.

Give every staff member a personal login with only the screens they need. Beyond fewer logout surprises, it makes User Logging meaningful, and it means an approval step for payments, discounts, salary changes or admissions genuinely involves a second person.

Attendance tablets, gate devices and sender phones are handled differently: they hold their own revocable device tokens, so a lost tablet is cut off without changing anyone's password. All portal, app and integration traffic runs over HTTPS.

  • One login per staff member, never a shared "office" account
  • Sign out at the end of a shift on counter and front-desk machines
  • Keep browsers reasonably current and stop cleaner tools from wiping site data
  • Train staff to save in stages on long entry screens

Common login and access symptoms and what usually causes them

SymptomMost likely causeWhat to do
Sent back to the login page mid-workSession expired after inactivitySign in again with institute code, username and password; re-enter unsaved data
"Page expired" on submitting a formForm's security token lapsed while the page sat openReload the screen to get a fresh page, then enter and save again
Logged out whenever a colleague signs inShared browser profile on a shared PCGive each staff member their own login and, ideally, their own device profile
Session lost every time the browser closesIncognito window or cookie-clearing settingsUse a normal window; exclude the portal from cleaner tools
Cannot sign in at allWrong institute code, username or passwordHave an admin reset the staff password from the portal
Screen missing after successful loginPrivileges or campus scope do not cover that screenReview the user's per-screen and per-action rights and campus access
Parent cannot open the Parents AppOne-time code not received on the registered mobileUse the Parent App OTP Portal to look up or issue the code; check the number on file
Gate tablet stops marking attendanceDevice credential revoked or removedCheck Registered Devices and re-issue a device token for that tablet

Related

Frequently asked questions

Do I lose saved work when the session expires?

No. Anything already saved is stored on the server and is unaffected. Only what you had typed into an open form and not yet saved has to be entered again.

Can the school turn off automatic logout?

Session expiry is a security control that protects screens with rights over fees, salaries and student records, so it is not something to disable. The practical answer is personal logins, saving in stages, and closing screens you are not actively using.

Why do parents not face the same login problem?

Parents log in to the Parents App with a rotating one-time code sent to their registered mobile rather than a shared password. If the code does not arrive, staff can look it up or issue it from the Parent App OTP Portal.

Who can reset a staff password?

Staff passwords are reset by an admin from the portal. Keep this with a small number of trusted people, because the same admin rights govern who can see and change other users' privileges.

How do I prove a record was not changed by someone using my login?

User Logging records who created, changed or deleted what, with severity levels, filters and a link that opens the record with the change highlighted. A daily summary of important changes also reaches the owner.

What if a laptop or attendance tablet is lost?

Attendance tablets, sender phones and gates hold their own revocable device tokens, so a lost device can be cut off without changing anyone's password. For a lost laptop, have an admin reset the affected staff passwords.

Where can staff get help with a login issue?

The in-app AI assistant answers how-to questions round the clock in English or Roman Urdu with links to the exact screen and tutorial video, and human support is available by WhatsApp group, phone and in-app request from 9:00 AM to 5:00 PM on working days.

Ready to see it on your own data?

Book a free demo, or message us on WhatsApp and we will reply in working hours.

Book a demo WhatsApp