Interface RememberMeServices
- All Known Implementing Classes:
PersistentTokenBasedRememberMeServices
public interface RememberMeServices
What remembers a user between sessions: issues the cookie at sign-in, and
recognizes it on a request nobody has signed in for.
-
Field Summary
FieldsModifier and TypeFieldDescriptionstatic final StringThe attribute of the request'sSecurityExchangethat says the user asked to be remembered, when the request that completes the sign-in is not the one that carried the checkbox: set toBoolean.TRUEbeforeloginSuccess(HttpServer.Request, Authentication)by whatever finishes a sign-in in a second step.static final StringThe attribute of the request'sSecurityExchangethat says the sign-in being completed passed a second factor: set toBoolean.TRUEbeforeloginSuccess(HttpServer.Request, Authentication). -
Method Summary
Modifier and TypeMethodDescriptionautoLogin(HttpServer.Request request) Recognizes the user from the request's cookie.voidloginFail(HttpServer.Request request) A sign-in was refused: withdraws the cookie.voidloginSuccess(HttpServer.Request request, Authentication successfulAuthentication) A user signed in: issues the cookie, if they asked to be remembered.
-
Field Details
-
REQUESTED_ATTRIBUTE
The attribute of the request'sSecurityExchangethat says the user asked to be remembered, when the request that completes the sign-in is not the one that carried the checkbox: set toBoolean.TRUEbeforeloginSuccess(HttpServer.Request, Authentication)by whatever finishes a sign-in in a second step.- See Also:
-
SECOND_FACTOR_ATTRIBUTE
The attribute of the request'sSecurityExchangethat says the sign-in being completed passed a second factor: set toBoolean.TRUEbeforeloginSuccess(HttpServer.Request, Authentication). A cookie issued then may sign a user who has a second factor in later; one issued without it may not. Services that issue cookies of their own carry this over, and say so on whatautoLogin(HttpServer.Request)returns -- seeRememberMeAuthenticationToken.isAfterSecondFactor().- See Also:
-
-
Method Details
-
autoLogin
Recognizes the user from the request's cookie.- Returns:
- who it is, or null when the request carries no cookie this accepts -- in which case the cookie, if there was one, is withdrawn
-
loginFail
A sign-in was refused: withdraws the cookie. -
loginSuccess
A user signed in: issues the cookie, if they asked to be remembered. Public so that a sign-in an application completes itself -- after a step of its own -- can issue it too.
-