Backend API. Server-side code: this runs in a Codename One backend, not in the app on the device.
public final class PersistentTokenBasedRememberMeServices
- Object
- PersistentTokenBasedRememberMeServices
ImplementsLogoutHandler, RememberMeServices
Remember-me with a series and a rotating token.
The cookie is series:token, both random. The server keeps the series and
a SHA-256 of the token. Presenting the cookie signs the user in and replaces
the token. For ten seconds after rotation, parallel requests can still use
the immediately preceding token without rotating again or overwriting the
winning response’s cookie. The grace is stored with the token, so it also
works across servers sharing a repository. An older or unrelated token
deletes every remembered sign-in of that user as a possible cookie theft.
A cookie issued by a sign-in that passed a second factor is recorded as
such, and only such a cookie signs in a user who has one; see
MfaConfigurer.
The cookie is HttpOnly, SameSite=Lax unless changed, and Secure when
the request that set it was.
Fields
public static final String DEFAULT_COOKIE_NAME = "remember-me" | The cookie’s name unless changed. |
public static final String DEFAULT_PARAMETER = "remember-me" | The form field that asks to be remembered unless changed. |
public static final int TWO_WEEKS_S = 1209600 | Two weeks, as in Spring Security. |
Constructors
public PersistentTokenBasedRememberMeServices(String key, UserDetailsService userDetailsService, PersistentTokenRepository tokenRepository) |
Methods
Inherited fields
Inherited methods
Field details
DEFAULT_COOKIE_NAME
public static final String DEFAULT_COOKIE_NAME = "remember-me"DEFAULT_PARAMETER
public static final String DEFAULT_PARAMETER = "remember-me"TWO_WEEKS_S
public static final int TWO_WEEKS_S = 1209600Constructor details
PersistentTokenBasedRememberMeServices
public PersistentTokenBasedRememberMeServices(String key, UserDetailsService userDetailsService, PersistentTokenRepository tokenRepository)Parameters
keyString- what identifies the tokens this makes; any text
userDetailsServiceUserDetailsService- Not documented.
tokenRepositoryPersistentTokenRepository- Not documented.
Method details
setCookieName
public void setCookieName(String cookieName)setParameter
public void setParameter(String parameter)setTokenValiditySeconds
public void setTokenValiditySeconds(int tokenValiditySeconds)setAlwaysRemember
public void setAlwaysRemember(boolean alwaysRemember)setUseSecureCookie
public void setUseSecureCookie(Boolean useSecureCookie)Secure; null, the default, for “when the request
was”.setSameSite
public void setSameSite(String sameSite)SameSite: Lax, Strict or None; null for none.setClock
public void setClock(Clock clock)getCookieName
public String getCookieName()getParameter
public String getParameter()autoLogin
public Authentication autoLogin(HttpServer.Request request)Returns
rememberMeRequested
public boolean rememberMeRequested(HttpServer.Request request)request asks for the user to be remembered: this is set to
remember always, the request’s exchange says so, or the form field is
true, on, yes or 1.loginSuccess
public void loginSuccess(HttpServer.Request request, Authentication successfulAuthentication)loginFail
public void loginFail(HttpServer.Request request)logout
public void logout(HttpServer.Request request, Authentication authentication)Parameters
requestHttpServer.Request- Not documented.
authenticationAuthentication- who is signing out; null when nobody was signed in
hash
public static String hash(String token)