Class JdbcTokenRepository
java.lang.Object
com.codename1.backend.security.rememberme.JdbcTokenRepository
- All Implemented Interfaces:
PersistentTokenRepository
Remembered sign-ins kept in the server's database, in the
cn1_persistent_logins table of SecuritySchema, so that any process of a
deployment recognizes a cookie any other issued.
http.rememberMe(remember -> remember.tokenRepository(new JdbcTokenRepository(dataSource)));
A token is replaced by one UPDATE that names the hash it expects to find,
and counted as replaced only when that changed exactly one row.
-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionvoidStores a new series.intdeleteExpired(long now, long olderThanSeconds) Deletes the series last used more thanolderThanSecondsago: for a scheduled job, since a cookie nobody presents again leaves its row behind.getTokenForSeries(String series) The stored token ofseries, or null.voidremoveToken(String series) Forgets one series: one browser.voidremoveUserTokens(String username) Forgets every series of a user: every browser they were remembered in.booleanupdateToken(String series, String expectedTokenHash, String newTokenHash, long lastUsed) Replaces the token ofseries, if it is stillexpectedTokenHash.
-
Constructor Details
-
JdbcTokenRepository
-
-
Method Details
-
createNewToken
Description copied from interface:PersistentTokenRepositoryStores a new series.- Specified by:
createNewTokenin interfacePersistentTokenRepository
-
updateToken
public boolean updateToken(String series, String expectedTokenHash, String newTokenHash, long lastUsed) Description copied from interface:PersistentTokenRepositoryReplaces the token of
series, if it is stillexpectedTokenHash.The test and the change are one step: of two requests presenting the same cookie at the same moment, one replaces the token and the other is told it did not. Store
expectedTokenHashas the previous hash of the replacement token, so concurrent requests can recognize the rotation for a bounded grace period.- Specified by:
updateTokenin interfacePersistentTokenRepository- Returns:
- whether this call replaced it
-
getTokenForSeries
Description copied from interface:PersistentTokenRepositoryThe stored token ofseries, or null.- Specified by:
getTokenForSeriesin interfacePersistentTokenRepository
-
removeToken
Description copied from interface:PersistentTokenRepositoryForgets one series: one browser.- Specified by:
removeTokenin interfacePersistentTokenRepository
-
removeUserTokens
Description copied from interface:PersistentTokenRepositoryForgets every series of a user: every browser they were remembered in.- Specified by:
removeUserTokensin interfacePersistentTokenRepository
-
deleteExpired
Deletes the series last used more thanolderThanSecondsago: for a scheduled job, since a cookie nobody presents again leaves its row behind.- Parameters:
now- epoch milliseconds- Returns:
- how many were deleted
- Throws:
IOException
-