Class RememberMeConfigurer
Remember-me: a cookie that signs a returning user in.
http.formLogin(Customizer.withDefaults())
.rememberMe(remember -> remember
.tokenRepository(new JdbcTokenRepository(dataSource))
.tokenValiditySeconds(30 * 24 * 3600));
A user who ticks remember-me on the login form is given the cookie, and
is signed in by it on a later visit without a session. They are then
authenticated but not fully: fullyAuthenticated() in the authorization
rules, and isFullyAuthenticated() in a @PreAuthorize, refuse them until
they sign in again. Signing out deletes the cookie and forgets the user in
every browser.
On a chain with a second factor -- HttpSecurity.mfa(Customizer) -- the cookie of a
user who has one signs them in only if it was issued by a sign-in that
passed it. One issued for a password alone, before the user enrolled, is
withdrawn when it is presented, and the user signs in again; see
MfaConfigurer.
Tokens are kept by a PersistentTokenRepository: the one given here, the
application's bean of that type, or one in memory -- which forgets everyone
when the server restarts, and is no use to a deployment of several
processes. Users are found through the chain's UserDetailsService.
See PersistentTokenBasedRememberMeServices for the cookie itself.
-
Method Summary
Modifier and TypeMethodDescriptionalwaysRemember(boolean alwaysRemember) Remembers every user who signs in, whether or not they asked.voidconfigure(HttpSecurity http) Adds this part's filters; nothing by default.The services of this chain: what a sign-in the application completes itself callsloginSuccesson.voidinit(HttpSecurity http) Shares what other parts need to know; nothing by default.What identifies the tokens of this chain.rememberMeCookieName(String rememberMeCookieName) The cookie's name;remember-meunless set.rememberMeParameter(String rememberMeParameter) The form field that asks to be remembered;remember-meunless set.rememberMeServices(RememberMeServices rememberMeServices) Services of the application's own, in place of everything else here.The cookie'sSameSite:Laxunless set; null for none.tokenRepository(PersistentTokenRepository tokenRepository) Where tokens are kept.tokenValiditySeconds(int tokenValiditySeconds) How long an unused cookie stays good; two weeks unless set.userDetailsService(UserDetailsService userDetailsService) Where a remembered user is looked up, in place of the chain's users.useSecureCookie(boolean useSecureCookie) Whether the cookie isSecure; when the request was, unless set.Methods inherited from class SecurityConfigurer
disable, getBuilder
-
Method Details
-
rememberMeServices
Services of the application's own, in place of everything else here. -
tokenRepository
Where tokens are kept. -
userDetailsService
Where a remembered user is looked up, in place of the chain's users. -
key
What identifies the tokens of this chain. -
rememberMeCookieName
The cookie's name;remember-meunless set. -
rememberMeParameter
The form field that asks to be remembered;remember-meunless set. -
tokenValiditySeconds
How long an unused cookie stays good; two weeks unless set. -
alwaysRemember
Remembers every user who signs in, whether or not they asked. -
useSecureCookie
Whether the cookie isSecure; when the request was, unless set. -
sameSite
The cookie'sSameSite:Laxunless set; null for none. -
getRememberMeServices
The services of this chain: what a sign-in the application completes itself callsloginSuccesson. Available once the chain is being built. -
init
Description copied from class:SecurityConfigurerShares what other parts need to know; nothing by default.- Overrides:
initin classSecurityConfigurer
-
configure
Description copied from class:SecurityConfigurerAdds this part's filters; nothing by default.- Overrides:
configurein classSecurityConfigurer
-