spring security - Remember-me cookie deleted after app restart - is this OK? -
i have remember-me implemented in spring boot app, can see cookie created correctly after login, proper expiration time etc. cookie doesnt survive app restart on tomcat server. scenario simple. user login remember me , cookie available in browser. app redeploy in tomcat , now, when user refreshes app in browser window, logged out , cookie deleted browser. shouldn't cookie survive , allow automatic login app restarts in tomcat?
here snippet springboot security config.
app.logout().deletecookies("nh_remember").logoutsuccessurl("/").logouturl("/logout").permitall().and().rememberme().remembermecookiename("nh_remember").tokenvalidityseconds(1209600).key("xxxxxxxx")
you have persist token between restarts of tomcat. check out documentation: http://docs.spring.io/spring-security/site/docs/current/reference/html/remember-me.html
specifically need setup persistenttokenbasedremembermeservices
contains information database persist tokens too.
Comments
Post a Comment