Class SessionSignIn

java.lang.Object
com.codename1.backend.security.SessionSignIn

public final class SessionSignIn extends Object

How a chain signs a user in to a session, once some mechanism has established who they are. One per chain, shared by every mechanism of it, so that each ends the same way:

  1. the chain's SecondFactorPolicy, if it has one, may hold the sign-in back and answer the request itself;
  2. the session id changes and the CSRF token is replaced;
  3. the authentication becomes the request's and is saved for later ones;
  4. what follows a sign-in is told -- remember-me issues its cookie;
  5. the mechanism's AuthenticationSuccessHandler answers.

A sign-in filter calls success(HttpServer.Request, Authentication, AuthenticationSuccessHandler) with what its AuthenticationManager returned, and failure(HttpServer.Request) when it was refused. What finishes a held-back sign-in -- the filter that takes the one-time code -- calls complete(HttpServer.Request, Authentication, boolean, AuthenticationSuccessHandler).