Backend API. Server-side code: this runs in a Codename One backend, not in the app on the device.
public final class FormLoginConfigurer
- Object
- SecurityConfigurer
- FormLoginConfigurer
Sign-in through an HTML form.
http.formLogin(form -> form
.loginPage("/signin")
.defaultSuccessUrl("/home")
.permitAll());
With nothing set, the chain serves a plain login page at GET /login, takes
the form at POST /login with the fields username and password, sends a
signed-in user back to the page that asked – or to / – and a refused one
to /login?error. Naming a loginPage hands the page to the application:
the chain then serves none, and takes the form at that same path.
Methods
Inherited methods
Method details
loginPage
public FormLoginConfigurer loginPage(String loginPage)The application’s own login page: a path the application serves.
loginProcessingUrl
public FormLoginConfigurer loginProcessingUrl(String loginProcessingUrl)Where the form is posted; the login page’s path unless set.
usernameParameter
public FormLoginConfigurer usernameParameter(String usernameParameter)passwordParameter
public FormLoginConfigurer passwordParameter(String passwordParameter)defaultSuccessUrl
public FormLoginConfigurer defaultSuccessUrl(String defaultSuccessUrl)Where a user goes after signing in when no page asked for the sign-in.
defaultSuccessUrl
public FormLoginConfigurer defaultSuccessUrl(String defaultSuccessUrl, boolean alwaysUse)Parameters
defaultSuccessUrlString- Not documented.
alwaysUseboolean- go there even when a page asked for the sign-in
failureUrl
public FormLoginConfigurer failureUrl(String failureUrl)Where a refused sign-in goes; the login page with
?error unless set.successHandler
public FormLoginConfigurer successHandler(AuthenticationSuccessHandler successHandler)Answers a sign-in itself, instead of the redirects.
failureHandler
public FormLoginConfigurer failureHandler(AuthenticationFailureHandler failureHandler)Answers a refused sign-in itself, instead of the redirect.
permitAll
public FormLoginConfigurer permitAll()Lets everyone reach the login page, the form’s target and the failure
page, whatever the authorization rules say. Needed with a
loginPage of
the application’s: without it anyRequest().authenticated() redirects
the login page to itself.init
public void init(HttpSecurity http)Shares what other parts need to know; nothing by default.
configure
public void configure(HttpSecurity http)Adds this part’s filters; nothing by default.