Backend API. Server-side code: this runs in a Codename One backend, not in the app on the device.

public final class PersistentTokenBasedRememberMeServices

  1. Object
  2. PersistentTokenBasedRememberMeServices

ImplementsLogoutHandler, RememberMeServices

Remember-me with a series and a rotating token.

The cookie is series:token, both random. The server keeps the series and a SHA-256 of the token. Presenting the cookie signs the user in and replaces the token. For ten seconds after rotation, parallel requests can still use the immediately preceding token without rotating again or overwriting the winning response’s cookie. The grace is stored with the token, so it also works across servers sharing a repository. An older or unrelated token deletes every remembered sign-in of that user as a possible cookie theft.

A cookie issued by a sign-in that passed a second factor is recorded as such, and only such a cookie signs in a user who has one; see MfaConfigurer.

The cookie is HttpOnly, SameSite=Lax unless changed, and Secure when the request that set it was.

Fields

public static final String DEFAULT_COOKIE_NAME = "remember-me"The cookie’s name unless changed.
public static final String DEFAULT_PARAMETER = "remember-me"The form field that asks to be remembered unless changed.
public static final int TWO_WEEKS_S = 1209600Two weeks, as in Spring Security.

Constructors

public PersistentTokenBasedRememberMeServices(String key, UserDetailsService userDetailsService, PersistentTokenRepository tokenRepository)

Methods

public void setCookieName(String cookieName)
public void setParameter(String parameter)
public void setTokenValiditySeconds(int tokenValiditySeconds)How long a cookie that is not used stays good; two weeks unless set.
public void setAlwaysRemember(boolean alwaysRemember)Remembers every user who signs in, whether or not they asked.
public void setUseSecureCookie(Boolean useSecureCookie)Whether the cookie is Secure; null, the default, for “when the request was”.
public void setSameSite(String sameSite)The cookie’s SameSite: Lax, Strict or None; null for none.
public void setClock(Clock clock)
public String getCookieName()
public String getParameter()
public Authentication autoLogin(HttpServer.Request request)Recognizes the user from the request’s cookie.
public boolean rememberMeRequested(HttpServer.Request request)Whether request asks for the user to be remembered: this is set to remember always, the request’s exchange says so, or the form field is true, on, yes or 1.
public void loginSuccess(HttpServer.Request request, Authentication successfulAuthentication)A user signed in: issues the cookie, if they asked to be remembered.
public void loginFail(HttpServer.Request request)A sign-in was refused: withdraws the cookie.
public void logout(HttpServer.Request request, Authentication authentication)Signing out forgets the user in every browser they were remembered in, as Spring Security does, and withdraws this browser’s cookie.
public static String hash(String token)The SHA-256 of a token, in hex: what the repository keeps.

Inherited fields

Inherited methods

Field details

DEFAULT_PARAMETER

public static final String DEFAULT_PARAMETER = "remember-me"
The form field that asks to be remembered unless changed.

TWO_WEEKS_S

public static final int TWO_WEEKS_S = 1209600
Two weeks, as in Spring Security.

Constructor details

PersistentTokenBasedRememberMeServices

public PersistentTokenBasedRememberMeServices(String key, UserDetailsService userDetailsService, PersistentTokenRepository tokenRepository)

Parameters

key String
what identifies the tokens this makes; any text
userDetailsService UserDetailsService
Not documented.
tokenRepository PersistentTokenRepository
Not documented.

Method details

setCookieName

public void setCookieName(String cookieName)

setParameter

public void setParameter(String parameter)

setTokenValiditySeconds

public void setTokenValiditySeconds(int tokenValiditySeconds)
How long a cookie that is not used stays good; two weeks unless set.

setAlwaysRemember

public void setAlwaysRemember(boolean alwaysRemember)
Remembers every user who signs in, whether or not they asked.

setUseSecureCookie

public void setUseSecureCookie(Boolean useSecureCookie)
Whether the cookie is Secure; null, the default, for “when the request was”.

setSameSite

public void setSameSite(String sameSite)
The cookie’s SameSite: Lax, Strict or None; null for none.

setClock

public void setClock(Clock clock)

getCookieName

public String getCookieName()

getParameter

public String getParameter()

autoLogin

public Authentication autoLogin(HttpServer.Request request)
Recognizes the user from the request’s cookie.

Returns

who it is, or null when the request carries no cookie this accepts – in which case the cookie, if there was one, is withdrawn

rememberMeRequested

public boolean rememberMeRequested(HttpServer.Request request)
Whether request asks for the user to be remembered: this is set to remember always, the request’s exchange says so, or the form field is true, on, yes or 1.

loginSuccess

public void loginSuccess(HttpServer.Request request, Authentication successfulAuthentication)
A user signed in: issues the cookie, if they asked to be remembered. Public so that a sign-in an application completes itself – after a step of its own – can issue it too.

loginFail

public void loginFail(HttpServer.Request request)
A sign-in was refused: withdraws the cookie.

logout

public void logout(HttpServer.Request request, Authentication authentication)
Signing out forgets the user in every browser they were remembered in, as Spring Security does, and withdraws this browser’s cookie.

Parameters

request HttpServer.Request
Not documented.
authentication Authentication
who is signing out; null when nobody was signed in

hash

public static String hash(String token)
The SHA-256 of a token, in hex: what the repository keeps.