Package com.codename1.backend.security.rememberme


package com.codename1.backend.security.rememberme

Remember-me: recognizing a returning user by a cookie, so that closing the browser does not sign them out.

http.rememberMe(...) turns it on for a chain. The cookie holds a series and a token, of which the server keeps only a hash; the token is replaced every time the cookie is used, and a cookie whose series is known but whose token is not is taken as stolen, which signs the user out everywhere. Tokens are kept by a PersistentTokenRepository: in memory, or in the server's database.

A user recognized this way is authenticated but not fully: see RememberMeAuthenticationToken.