Class RememberMeConfigurer

java.lang.Object
com.codename1.backend.security.SecurityConfigurer
com.codename1.backend.security.RememberMeConfigurer

public final class RememberMeConfigurer extends SecurityConfigurer

Remember-me: a cookie that signs a returning user in.

http.formLogin(Customizer.withDefaults())
    .rememberMe(remember -> remember
            .tokenRepository(new JdbcTokenRepository(dataSource))
            .tokenValiditySeconds(30 * 24 * 3600));

A user who ticks remember-me on the login form is given the cookie, and is signed in by it on a later visit without a session. They are then authenticated but not fully: fullyAuthenticated() in the authorization rules, and isFullyAuthenticated() in a @PreAuthorize, refuse them until they sign in again. Signing out deletes the cookie and forgets the user in every browser.

On a chain with a second factor -- HttpSecurity.mfa(Customizer) -- the cookie of a user who has one signs them in only if it was issued by a sign-in that passed it. One issued for a password alone, before the user enrolled, is withdrawn when it is presented, and the user signs in again; see MfaConfigurer.

Tokens are kept by a PersistentTokenRepository: the one given here, the application's bean of that type, or one in memory -- which forgets everyone when the server restarts, and is no use to a deployment of several processes. Users are found through the chain's UserDetailsService.

See PersistentTokenBasedRememberMeServices for the cookie itself.

  • Method Details

    • rememberMeServices

      public RememberMeConfigurer rememberMeServices(RememberMeServices rememberMeServices)
      Services of the application's own, in place of everything else here.
    • tokenRepository

      public RememberMeConfigurer tokenRepository(PersistentTokenRepository tokenRepository)
      Where tokens are kept.
    • userDetailsService

      public RememberMeConfigurer userDetailsService(UserDetailsService userDetailsService)
      Where a remembered user is looked up, in place of the chain's users.
    • key

      public RememberMeConfigurer key(String key)
      What identifies the tokens of this chain.
    • rememberMeCookieName

      public RememberMeConfigurer rememberMeCookieName(String rememberMeCookieName)
      The cookie's name; remember-me unless set.
    • rememberMeParameter

      public RememberMeConfigurer rememberMeParameter(String rememberMeParameter)
      The form field that asks to be remembered; remember-me unless set.
    • tokenValiditySeconds

      public RememberMeConfigurer tokenValiditySeconds(int tokenValiditySeconds)
      How long an unused cookie stays good; two weeks unless set.
    • alwaysRemember

      public RememberMeConfigurer alwaysRemember(boolean alwaysRemember)
      Remembers every user who signs in, whether or not they asked.
    • useSecureCookie

      public RememberMeConfigurer useSecureCookie(boolean useSecureCookie)
      Whether the cookie is Secure; when the request was, unless set.
    • sameSite

      public RememberMeConfigurer sameSite(String sameSite)
      The cookie's SameSite: Lax unless set; null for none.
    • getRememberMeServices

      public RememberMeServices getRememberMeServices()
      The services of this chain: what a sign-in the application completes itself calls loginSuccess on. Available once the chain is being built.
    • init

      public void init(HttpSecurity http)
      Description copied from class: SecurityConfigurer
      Shares what other parts need to know; nothing by default.
      Overrides:
      init in class SecurityConfigurer
    • configure

      public void configure(HttpSecurity http)
      Description copied from class: SecurityConfigurer
      Adds this part's filters; nothing by default.
      Overrides:
      configure in class SecurityConfigurer