[Security] user session control
features like:
idle session timeout,
admin force logout,
limit the number of concurrent sessions of same ID (so no share account),
restricted / limited access by user's IP addresses / countries (risky countries like PR )