Class RememberMeAuthenticationFilter

java.lang.Object
com.codename1.backend.security.RememberMeAuthenticationFilter
All Implemented Interfaces:
SecurityFilter

public final class RememberMeAuthenticationFilter extends Object implements SecurityFilter

Recognizes a returning user by their remember-me cookie, on a request nobody has signed in for.

A request that already has an authentication -- from its session, or from a credential it carried -- is left alone. Otherwise the chain's RememberMeServices are asked; when they recognize the user, the authentication becomes the request's and is saved, so the session that starts here carries it and the cookie is not consulted again until that session ends.

On a chain with a SecondFactorPolicy, a user the policy requires a second factor of is recognized only by a cookie issued after one. Any other cookie of theirs is withdrawn and the request stays anonymous: a cookie is not a way around the code.