Backend API. Server-side code: this runs in a Codename One backend, not in the app on the device.
public interface RememberMeServices
Known subtypesPersistentTokenBasedRememberMeServices
What remembers a user between sessions: issues the cookie at sign-in, and
recognizes it on a request nobody has signed in for.
Fields
public static final String REQUESTED_ATTRIBUTE = "com.codename1.backend.security.rememberMe.requested" | The attribute of the request’s SecurityExchange that says the user asked to be remembered, when the request that completes the sign-in is not the one that carried the checkbox: set to Boolean.TRUE before loginSuccess by whatever finishes a sign-in in a second step. |
public static final String SECOND_FACTOR_ATTRIBUTE = "com.codename1.backend.security.rememberMe.secondFactor" | The attribute of the request’s SecurityExchange that says the sign-in being completed passed a second factor: set to Boolean.TRUE before loginSuccess. |
Methods
Field details
REQUESTED_ATTRIBUTE
public static final String REQUESTED_ATTRIBUTE = "com.codename1.backend.security.rememberMe.requested"The attribute of the request’s
SecurityExchange that says the user
asked to be remembered, when the request that completes the sign-in is
not the one that carried the checkbox: set to Boolean.TRUE before
loginSuccess by whatever finishes a sign-in in a second step.SECOND_FACTOR_ATTRIBUTE
public static final String SECOND_FACTOR_ATTRIBUTE = "com.codename1.backend.security.rememberMe.secondFactor"The attribute of the request’s
SecurityExchange that says the sign-in
being completed passed a second factor: set to Boolean.TRUE before
loginSuccess. A cookie issued then may sign a user who has a second
factor in later; one issued without it may not. Services that issue
cookies of their own carry this over, and say so on what autoLogin
returns – see
RememberMeAuthenticationToken.isAfterSecondFactor.Method details
autoLogin
public abstract Authentication autoLogin(HttpServer.Request request)Recognizes the user from the request’s cookie.
Returns
who it is, or null when the request carries no cookie this
accepts – in which case the cookie, if there was one, is withdrawn
loginFail
public abstract void loginFail(HttpServer.Request request)A sign-in was refused: withdraws the cookie.
loginSuccess
public abstract void loginSuccess(HttpServer.Request request, Authentication successfulAuthentication)A user signed in: issues the cookie, if they asked to be remembered.
Public so that a sign-in an application completes itself – after a
step of its own – can issue it too.