Class PersistentTokenBasedRememberMeServices

java.lang.Object
com.codename1.backend.security.rememberme.PersistentTokenBasedRememberMeServices
All Implemented Interfaces:
LogoutHandler, RememberMeServices

public final class PersistentTokenBasedRememberMeServices extends Object implements RememberMeServices, LogoutHandler

Remember-me with a series and a rotating token.

The cookie is series:token, both random. The server keeps the series and a SHA-256 of the token. Presenting the cookie signs the user in and replaces the token. For ten seconds after rotation, parallel requests can still use the immediately preceding token without rotating again or overwriting the winning response's cookie. The grace is stored with the token, so it also works across servers sharing a repository. An older or unrelated token deletes every remembered sign-in of that user as a possible cookie theft.

A cookie issued by a sign-in that passed a second factor is recorded as such, and only such a cookie signs in a user who has one; see MfaConfigurer.

The cookie is HttpOnly, SameSite=Lax unless changed, and Secure when the request that set it was.

  • Field Details

    • DEFAULT_PARAMETER

      public static final String DEFAULT_PARAMETER
      The form field that asks to be remembered unless changed.
      See Also:
    • TWO_WEEKS_S

      public static final int TWO_WEEKS_S
      Two weeks, as in Spring Security.
      See Also:
  • Constructor Details

    • PersistentTokenBasedRememberMeServices

      public PersistentTokenBasedRememberMeServices(String key, UserDetailsService userDetailsService, PersistentTokenRepository tokenRepository)
      Parameters:
      key - what identifies the tokens this makes; any text
  • Method Details

    • setCookieName

      public void setCookieName(String cookieName)
    • setParameter

      public void setParameter(String parameter)
    • setTokenValiditySeconds

      public void setTokenValiditySeconds(int tokenValiditySeconds)
      How long a cookie that is not used stays good; two weeks unless set.
    • setAlwaysRemember

      public void setAlwaysRemember(boolean alwaysRemember)
      Remembers every user who signs in, whether or not they asked.
    • setUseSecureCookie

      public void setUseSecureCookie(Boolean useSecureCookie)
      Whether the cookie is Secure; null, the default, for "when the request was".
    • setSameSite

      public void setSameSite(String sameSite)
      The cookie's SameSite: Lax, Strict or None; null for none.
    • setClock

      public void setClock(Clock clock)
    • getCookieName

      public String getCookieName()
    • getParameter

      public String getParameter()
    • autoLogin

      public Authentication autoLogin(HttpServer.Request request)
      Description copied from interface: RememberMeServices
      Recognizes the user from the request's cookie.
      Specified by:
      autoLogin in interface RememberMeServices
      Returns:
      who it is, or null when the request carries no cookie this accepts -- in which case the cookie, if there was one, is withdrawn
    • rememberMeRequested

      public boolean rememberMeRequested(HttpServer.Request request)
      Whether request asks for the user to be remembered: this is set to remember always, the request's exchange says so, or the form field is true, on, yes or 1.
    • loginSuccess

      public void loginSuccess(HttpServer.Request request, Authentication successfulAuthentication)
      Description copied from interface: RememberMeServices
      A user signed in: issues the cookie, if they asked to be remembered. Public so that a sign-in an application completes itself -- after a step of its own -- can issue it too.
      Specified by:
      loginSuccess in interface RememberMeServices
    • loginFail

      public void loginFail(HttpServer.Request request)
      Description copied from interface: RememberMeServices
      A sign-in was refused: withdraws the cookie.
      Specified by:
      loginFail in interface RememberMeServices
    • logout

      public void logout(HttpServer.Request request, Authentication authentication)
      Signing out forgets the user in every browser they were remembered in, as Spring Security does, and withdraws this browser's cookie.
      Specified by:
      logout in interface LogoutHandler
      Parameters:
      authentication - who is signing out; null when nobody was signed in
    • hash

      public static String hash(String token)
      The SHA-256 of a token, in hex: what the repository keeps.