Package com.codename1.backend.security.rememberme
package com.codename1.backend.security.rememberme
Remember-me: recognizing a returning user by a cookie, so that closing the browser does not sign them out.
http.rememberMe(...) turns it on for a chain. The cookie holds a series
and a token, of which the server keeps only a hash; the token is replaced
every time the cookie is used, and a cookie whose series is known but whose
token is not is taken as stolen, which signs the user out everywhere. Tokens
are kept by a PersistentTokenRepository:
in memory, or in the server's database.
A user recognized this way is authenticated but not fully: see
RememberMeAuthenticationToken.
-
ClassDescriptionRemembered sign-ins kept in this process: gone when it stops, and unknown to any other process of the same deployment.Remembered sign-ins kept in the server's database, in the
cn1_persistent_loginstable ofSecuritySchema, so that any process of a deployment recognizes a cookie any other issued.One remembered sign-in, as the server keeps it: whose it is, the series the cookie names, the hash of the token the cookie must carry next, and when it was last used.Remember-me with a series and a rotating token.Where remembered sign-ins are kept.What remembers a user between sessions: issues the cookie at sign-in, and recognizes it on a request nobody has signed in for.