Class HttpSessionSecurityContextRepository

java.lang.Object
com.codename1.backend.security.HttpSessionSecurityContextRepository
All Implemented Interfaces:
SecurityContextRepository

public class HttpSessionSecurityContextRepository extends Object implements SecurityContextRepository

Keeps who is signed in in the HTTP session, under SPRING_SECURITY_CONTEXT_KEY.

What is stored is a map of plain values -- the name, the authorities, whether the authentication is trusted, and its details when they are plain values too -- rather than the Authentication itself. The database session store keeps what JSON can write and hands it to whichever server takes the client's next request, so an object would not survive the trip, and a server whose sessions are in memory behaves the same way so that moving to the database changes nothing.

The consequence: on a later request the principal is a User rebuilt from the name and authorities, with no password, not the object the user store returned at sign-in.

A way of signing in whose authentication is a kind of its own -- a user of another identity provider, a passkey -- keeps that kind through an AuthenticationCodec, which its configurer registers with HttpSecurity.authenticationCodec(AuthenticationCodec); see there. A subclass that needs something else again overrides toMap(Authentication) and fromMap(Map).