Interface PersistentTokenRepository
- All Known Implementing Classes:
InMemoryTokenRepositoryImpl, JdbcTokenRepository
public interface PersistentTokenRepository
Where remembered sign-ins are kept.
-
Method Summary
Modifier and TypeMethodDescriptionvoidStores a new series.getTokenForSeries(String series) The stored token ofseries, or null.voidremoveToken(String series) Forgets one series: one browser.voidremoveUserTokens(String username) Forgets every series of a user: every browser they were remembered in.booleanupdateToken(String series, String expectedTokenHash, String newTokenHash, long lastUsed) Replaces the token ofseries, if it is stillexpectedTokenHash.
-
Method Details
-
createNewToken
Stores a new series. -
updateToken
Replaces the token of
series, if it is stillexpectedTokenHash.The test and the change are one step: of two requests presenting the same cookie at the same moment, one replaces the token and the other is told it did not. Store
expectedTokenHashas the previous hash of the replacement token, so concurrent requests can recognize the rotation for a bounded grace period.- Returns:
- whether this call replaced it
-
getTokenForSeries
The stored token ofseries, or null. -
removeToken
Forgets one series: one browser. -
removeUserTokens
Forgets every series of a user: every browser they were remembered in.
-