Interface PersistentTokenRepository

All Known Implementing Classes:
InMemoryTokenRepositoryImpl, JdbcTokenRepository

public interface PersistentTokenRepository
Where remembered sign-ins are kept.
  • Method Details

    • createNewToken

      void createNewToken(PersistentRememberMeToken token)
      Stores a new series.
    • updateToken

      boolean updateToken(String series, String expectedTokenHash, String newTokenHash, long lastUsed)

      Replaces the token of series, if it is still expectedTokenHash.

      The test and the change are one step: of two requests presenting the same cookie at the same moment, one replaces the token and the other is told it did not. Store expectedTokenHash as the previous hash of the replacement token, so concurrent requests can recognize the rotation for a bounded grace period.

      Returns:
      whether this call replaced it
    • getTokenForSeries

      PersistentRememberMeToken getTokenForSeries(String series)
      The stored token of series, or null.
    • removeToken

      void removeToken(String series)
      Forgets one series: one browser.
    • removeUserTokens

      void removeUserTokens(String username)
      Forgets every series of a user: every browser they were remembered in.