Class PersistentTokenBasedRememberMeServices
- All Implemented Interfaces:
LogoutHandler, RememberMeServices
Remember-me with a series and a rotating token.
The cookie is series:token, both random. The server keeps the series and
a SHA-256 of the token. Presenting the cookie signs the user in and replaces
the token. For ten seconds after rotation, parallel requests can still use
the immediately preceding token without rotating again or overwriting the
winning response's cookie. The grace is stored with the token, so it also
works across servers sharing a repository. An older or unrelated token
deletes every remembered sign-in of that user as a possible cookie theft.
A cookie issued by a sign-in that passed a second factor is recorded as
such, and only such a cookie signs in a user who has one; see
MfaConfigurer.
The cookie is HttpOnly, SameSite=Lax unless changed, and Secure when
the request that set it was.
-
Field Summary
FieldsModifier and TypeFieldDescriptionstatic final StringThe cookie's name unless changed.static final StringThe form field that asks to be remembered unless changed.static final intTwo weeks, as in Spring Security.Fields inherited from interface RememberMeServices
REQUESTED_ATTRIBUTE, SECOND_FACTOR_ATTRIBUTE -
Constructor Summary
ConstructorsConstructorDescriptionPersistentTokenBasedRememberMeServices(String key, UserDetailsService userDetailsService, PersistentTokenRepository tokenRepository) -
Method Summary
Modifier and TypeMethodDescriptionautoLogin(HttpServer.Request request) Recognizes the user from the request's cookie.static StringThe SHA-256 of a token, in hex: what the repository keeps.voidloginFail(HttpServer.Request request) A sign-in was refused: withdraws the cookie.voidloginSuccess(HttpServer.Request request, Authentication successfulAuthentication) A user signed in: issues the cookie, if they asked to be remembered.voidlogout(HttpServer.Request request, Authentication authentication) Signing out forgets the user in every browser they were remembered in, as Spring Security does, and withdraws this browser's cookie.booleanrememberMeRequested(HttpServer.Request request) Whetherrequestasks for the user to be remembered: this is set to remember always, the request's exchange says so, or the form field istrue,on,yesor1.voidsetAlwaysRemember(boolean alwaysRemember) Remembers every user who signs in, whether or not they asked.voidvoidsetCookieName(String cookieName) voidsetParameter(String parameter) voidsetSameSite(String sameSite) The cookie'sSameSite:Lax,StrictorNone; null for none.voidsetTokenValiditySeconds(int tokenValiditySeconds) How long a cookie that is not used stays good; two weeks unless set.voidsetUseSecureCookie(Boolean useSecureCookie) Whether the cookie isSecure; null, the default, for "when the request was".
-
Field Details
-
DEFAULT_COOKIE_NAME
-
DEFAULT_PARAMETER
The form field that asks to be remembered unless changed.- See Also:
-
TWO_WEEKS_S
public static final int TWO_WEEKS_STwo weeks, as in Spring Security.- See Also:
-
-
Constructor Details
-
PersistentTokenBasedRememberMeServices
public PersistentTokenBasedRememberMeServices(String key, UserDetailsService userDetailsService, PersistentTokenRepository tokenRepository) - Parameters:
key- what identifies the tokens this makes; any text
-
-
Method Details
-
setCookieName
-
setParameter
-
setTokenValiditySeconds
public void setTokenValiditySeconds(int tokenValiditySeconds) How long a cookie that is not used stays good; two weeks unless set. -
setAlwaysRemember
public void setAlwaysRemember(boolean alwaysRemember) Remembers every user who signs in, whether or not they asked. -
setUseSecureCookie
Whether the cookie isSecure; null, the default, for "when the request was". -
setSameSite
The cookie'sSameSite:Lax,StrictorNone; null for none. -
setClock
-
getCookieName
-
getParameter
-
autoLogin
Description copied from interface:RememberMeServicesRecognizes the user from the request's cookie.- Specified by:
autoLoginin interfaceRememberMeServices- Returns:
- who it is, or null when the request carries no cookie this accepts -- in which case the cookie, if there was one, is withdrawn
-
rememberMeRequested
Whetherrequestasks for the user to be remembered: this is set to remember always, the request's exchange says so, or the form field istrue,on,yesor1. -
loginSuccess
Description copied from interface:RememberMeServicesA user signed in: issues the cookie, if they asked to be remembered. Public so that a sign-in an application completes itself -- after a step of its own -- can issue it too.- Specified by:
loginSuccessin interfaceRememberMeServices
-
loginFail
Description copied from interface:RememberMeServicesA sign-in was refused: withdraws the cookie.- Specified by:
loginFailin interfaceRememberMeServices
-
logout
Signing out forgets the user in every browser they were remembered in, as Spring Security does, and withdraws this browser's cookie.- Specified by:
logoutin interfaceLogoutHandler- Parameters:
authentication- who is signing out; null when nobody was signed in
-
hash
-