2.2.5 Re-authenticating
When an authenticated session expires, the user can continue the activity without loss of data after re-authenticating.
Last reviewed: September 9, 2026
Understanding 2.2.5
When an authenticated session times out for security reasons, users (particularly those who take longer to complete tasks due to cognitive or motor disabilities) can lose significant work if forced to start over after logging back in. This criterion requires that in-progress data be preserved through the re-authentication process so users can resume exactly where they left off.
How to Meet It
Code Examples
// Session expires and redirects straight to login with no data preserved
if (sessionExpired) {
window.location.href = '/login'; // Any unsaved form data is lost
}if (sessionExpired) {
localStorage.setItem('draftForm', JSON.stringify(getFormData()));
window.location.href = '/login?returnTo=' + encodeURIComponent(window.location.href);
}
// On the return page after re-authentication:
window.addEventListener('load', function() {
const draft = localStorage.getItem('draftForm');
if (draft) {
populateForm(JSON.parse(draft));
localStorage.removeItem('draftForm');
}
});Frequently Asked Questions
Does this mean session timeouts themselves are prohibited at AAA?
No. 2.2.5 doesn't forbid session timeouts; it requires that when one does occur, the user doesn't lose in-progress data as a result of having to re-authenticate. This is distinct from 2.2.1 and 2.2.3, which govern the time limit itself rather than what happens to unsaved work.
Related Success Criteria
Quick Facts
- Criterion2.2.5
- LevelAAA
- IntroducedWCAG 2.0
Automate Compliance
AccessiSight automatically scans and identifies 2.2.5 issues in your codebase.
Try Scanner Free