Backend API. Server-side code: this runs in a Codename One backend, not in the app on the device.
public final class SessionSignIn
- Object
- SessionSignIn
How a chain signs a user in to a session, once some mechanism has established who they are. One per chain, shared by every mechanism of it, so that each ends the same way:
- the chain’s
SecondFactorPolicy, if it has one, may hold the sign-in back and answer the request itself; - the session id changes and the CSRF token is replaced;
- the authentication becomes the request’s and is saved for later ones;
- what follows a sign-in is told – remember-me issues its cookie;
- the mechanism’s
AuthenticationSuccessHandleranswers.
A sign-in filter calls success with what its AuthenticationManager
returned, and failure when it was refused. What finishes a held-back
sign-in – the filter that takes the one-time code – calls complete.
Methods
Inherited methods
Method details
success
public HttpServer.Response success(HttpServer.Request request, Authentication authentication, AuthenticationSuccessHandler handler)
throws Exceptionauthentication: signs the user in, unless the
chain asks for a second factor first.Returns
Throws
success
public HttpServer.Response success(HttpServer.Request request, Authentication authentication, AuthenticationSuccessHandler handler, boolean secondFactorSatisfied)
throws ExceptionA mechanism accepted authentication, and says whether what it checked
was two factors already.
A passkey whose authenticator verified the user – a fingerprint, a
PIN – is something they have and something they are or know, in one
step: asking for a one-time code after it would add nothing, so the
chain’s SecondFactorPolicy is not consulted. A mechanism that checked
one factor passes false, and the policy decides as it does for a
password.
Parameters
requestHttpServer.Request- Not documented.
authenticationAuthentication- Not documented.
handlerAuthenticationSuccessHandler- Not documented.
secondFactorSatisfiedboolean- true when the sign-in needs no second factor whatever the chain’s policy would say
Returns
Throws
complete
public HttpServer.Response complete(HttpServer.Request request, Authentication authentication, boolean rememberMe, AuthenticationSuccessHandler handler)
throws ExceptionParameters
requestHttpServer.Request- Not documented.
authenticationAuthentication- Not documented.
rememberMeboolean- what
SecondFactorPolicy.interceptwas told handlerAuthenticationSuccessHandler- Not documented.
Throws
complete
public HttpServer.Response complete(HttpServer.Request request, Authentication authentication, boolean rememberMe, AuthenticationSuccessHandler handler, boolean secondFactor)
throws ExceptionMfaConfigurer.Parameters
requestHttpServer.Request- Not documented.
authenticationAuthentication- Not documented.
rememberMeboolean- what
SecondFactorPolicy.interceptwas told handlerAuthenticationSuccessHandler- Not documented.
secondFactorboolean- whether the user presented a second factor
Throws
failure
public void failure(HttpServer.Request request)