Backend API. Server-side code: this runs in a Codename One backend, not in the app on the device.

public final class FormLoginConfigurer

  1. Object
  2. SecurityConfigurer
  3. FormLoginConfigurer

Sign-in through an HTML form.

http.formLogin(form -> form
        .loginPage("/signin")
        .defaultSuccessUrl("/home")
        .permitAll());

With nothing set, the chain serves a plain login page at GET /login, takes the form at POST /login with the fields username and password, sends a signed-in user back to the page that asked – or to / – and a refused one to /login?error. Naming a loginPage hands the page to the application: the chain then serves none, and takes the form at that same path.

Methods

public FormLoginConfigurer loginPage(String loginPage)The application’s own login page: a path the application serves.
public FormLoginConfigurer loginProcessingUrl(String loginProcessingUrl)Where the form is posted; the login page’s path unless set.
public FormLoginConfigurer usernameParameter(String usernameParameter)
public FormLoginConfigurer passwordParameter(String passwordParameter)
public FormLoginConfigurer defaultSuccessUrl(String defaultSuccessUrl)Where a user goes after signing in when no page asked for the sign-in.
public FormLoginConfigurer defaultSuccessUrl(String defaultSuccessUrl, boolean alwaysUse)
public FormLoginConfigurer failureUrl(String failureUrl)Where a refused sign-in goes; the login page with ?error unless set.
public FormLoginConfigurer successHandler(AuthenticationSuccessHandler successHandler)Answers a sign-in itself, instead of the redirects.
public FormLoginConfigurer failureHandler(AuthenticationFailureHandler failureHandler)Answers a refused sign-in itself, instead of the redirect.
public FormLoginConfigurer permitAll()Lets everyone reach the login page, the form’s target and the failure page, whatever the authorization rules say.
public void init(HttpSecurity http)Shares what other parts need to know; nothing by default.
public void configure(HttpSecurity http)Adds this part’s filters; nothing by default.

Inherited methods

Method details

loginPage

public FormLoginConfigurer loginPage(String loginPage)
The application’s own login page: a path the application serves.

loginProcessingUrl

public FormLoginConfigurer loginProcessingUrl(String loginProcessingUrl)
Where the form is posted; the login page’s path unless set.

usernameParameter

public FormLoginConfigurer usernameParameter(String usernameParameter)

passwordParameter

public FormLoginConfigurer passwordParameter(String passwordParameter)

defaultSuccessUrl

public FormLoginConfigurer defaultSuccessUrl(String defaultSuccessUrl)
Where a user goes after signing in when no page asked for the sign-in.

defaultSuccessUrl

public FormLoginConfigurer defaultSuccessUrl(String defaultSuccessUrl, boolean alwaysUse)

Parameters

defaultSuccessUrl String
Not documented.
alwaysUse boolean
go there even when a page asked for the sign-in

failureUrl

public FormLoginConfigurer failureUrl(String failureUrl)
Where a refused sign-in goes; the login page with ?error unless set.

successHandler

public FormLoginConfigurer successHandler(AuthenticationSuccessHandler successHandler)
Answers a sign-in itself, instead of the redirects.

failureHandler

public FormLoginConfigurer failureHandler(AuthenticationFailureHandler failureHandler)
Answers a refused sign-in itself, instead of the redirect.

permitAll

public FormLoginConfigurer permitAll()
Lets everyone reach the login page, the form’s target and the failure page, whatever the authorization rules say. Needed with a loginPage of the application’s: without it anyRequest().authenticated() redirects the login page to itself.

init

public void init(HttpSecurity http)
Shares what other parts need to know; nothing by default.

configure

public void configure(HttpSecurity http)
Adds this part’s filters; nothing by default.