java - JSESSIONID not expired, SPRING_SECURITY_REMEMBER_ME expired -



java - JSESSIONID not expired, SPRING_SECURITY_REMEMBER_ME expired -

so, have in application spring security , have introduced remember me functionality when checkbox checked in.

i wanted know exact behavior: if set </remember-me> tag , specify remembermeservices tokenvalidityseconds 20 seconds, shouldn't session expire , and inquire me log in again? have set:

<session-config> <session-timeout>xx</session-timeout> </session-config>

so matches spring_security_remember_me cookie tokenvalidityseconds ?

update

does matter if i've implemented own persistenttokenbasedremembermeservices? had override default persistenttokenbasedremembermeservices coming spring, because persistentremembermetoken did not have no-arg constructor, unable utilize hibernate that, did wrote own persistentremembermetoken, persistenttokenbasedremembermeservices (which, way, no have special beside me introducing no-arg constructor in persistentremembermetoken, beside that, it's re-create paste spring's source)

having remember-me token valid less session-timeout have no effect on authentication during session, if that's asking.

once authenticated during session, authentication valid duration of session, unless log out or session expires.

the remember-me token considered if unauthenticated, otherwise ignored.

java spring-security session-cookies

Comments

Popular posts from this blog

web services - java.lang.NoClassDefFoundError: Could not initialize class net.sf.cglib.proxy.Enhancer -

Accessing MATLAB's unicode strings from C -

javascript - mongodb won't find my schema method in nested container -