Backend API. Server-side code: this runs in a Codename One backend, not in the app on the device.

public final class SessionSignIn

  1. Object
  2. SessionSignIn

How a chain signs a user in to a session, once some mechanism has established who they are. One per chain, shared by every mechanism of it, so that each ends the same way:

  1. the chain’s SecondFactorPolicy, if it has one, may hold the sign-in back and answer the request itself;
  2. the session id changes and the CSRF token is replaced;
  3. the authentication becomes the request’s and is saved for later ones;
  4. what follows a sign-in is told – remember-me issues its cookie;
  5. the mechanism’s AuthenticationSuccessHandler answers.

A sign-in filter calls success with what its AuthenticationManager returned, and failure when it was refused. What finishes a held-back sign-in – the filter that takes the one-time code – calls complete.

Methods

public HttpServer.Response success(HttpServer.Request request, Authentication authentication, AuthenticationSuccessHandler handler) throws ExceptionA mechanism accepted authentication: signs the user in, unless the chain asks for a second factor first.
public HttpServer.Response success(HttpServer.Request request, Authentication authentication, AuthenticationSuccessHandler handler, boolean secondFactorSatisfied) throws ExceptionA mechanism accepted authentication, and says whether what it checked was two factors already.
public HttpServer.Response complete(HttpServer.Request request, Authentication authentication, boolean rememberMe, AuthenticationSuccessHandler handler) throws ExceptionSigns the user in, with no second factor asked: for the first factor of a chain without one, and for whatever finishes a sign-in that was held back.
public HttpServer.Response complete(HttpServer.Request request, Authentication authentication, boolean rememberMe, AuthenticationSuccessHandler handler, boolean secondFactor) throws ExceptionSigns the user in, and says whether a second factor was part of it.
public void failure(HttpServer.Request request)A mechanism refused the credentials it was given.

Inherited methods

Method details

success

public HttpServer.Response success(HttpServer.Request request, Authentication authentication, AuthenticationSuccessHandler handler) throws Exception
A mechanism accepted authentication: signs the user in, unless the chain asks for a second factor first.

Returns

the answer to the request

Throws

Exception

success

public HttpServer.Response success(HttpServer.Request request, Authentication authentication, AuthenticationSuccessHandler handler, boolean secondFactorSatisfied) throws Exception

A mechanism accepted authentication, and says whether what it checked was two factors already.

A passkey whose authenticator verified the user – a fingerprint, a PIN – is something they have and something they are or know, in one step: asking for a one-time code after it would add nothing, so the chain’s SecondFactorPolicy is not consulted. A mechanism that checked one factor passes false, and the policy decides as it does for a password.

Parameters

request HttpServer.Request
Not documented.
authentication Authentication
Not documented.
handler AuthenticationSuccessHandler
Not documented.
secondFactorSatisfied boolean
true when the sign-in needs no second factor whatever the chain’s policy would say

Returns

the answer to the request

Throws

Exception

complete

public HttpServer.Response complete(HttpServer.Request request, Authentication authentication, boolean rememberMe, AuthenticationSuccessHandler handler) throws Exception
Signs the user in, with no second factor asked: for the first factor of a chain without one, and for whatever finishes a sign-in that was held back.

Parameters

request HttpServer.Request
Not documented.
authentication Authentication
Not documented.
rememberMe boolean
what SecondFactorPolicy.intercept was told
handler AuthenticationSuccessHandler
Not documented.

Throws

Exception

complete

public HttpServer.Response complete(HttpServer.Request request, Authentication authentication, boolean rememberMe, AuthenticationSuccessHandler handler, boolean secondFactor) throws Exception
Signs the user in, and says whether a second factor was part of it. What finishes a sign-in that was held back passes true, and so a remember-me cookie issued here is one that may stand for both factors later; see MfaConfigurer.

Parameters

request HttpServer.Request
Not documented.
authentication Authentication
Not documented.
rememberMe boolean
what SecondFactorPolicy.intercept was told
handler AuthenticationSuccessHandler
Not documented.
secondFactor boolean
whether the user presented a second factor

Throws

Exception

failure

public void failure(HttpServer.Request request)
A mechanism refused the credentials it was given.