Class Sessions
How a server keeps HttpSessions: the cookie, the lifetime and the
store, read from configuration when the server starts.
cn1.session.cookie=CN1SESSION # the cookie's name
cn1.session.timeout=1800 # seconds of inactivity, 0 for never
cn1.session.store=memory # or db
cn1.session.same-site=Lax # Lax, Strict or None
cn1.session.secure=auto # true, false, or auto (on under TLS)
Nothing here runs for a request that does not ask for its session: the
cookie is parsed on the first getSession, and a request that never
calls it costs one field check when it ends.
-
Nested Class Summary
Nested ClassesModifier and TypeClassDescriptionstatic final classSessions in the server's database, incn1_http_session, so every instance of a server sees every session.static final classSessions in this process's memory. -
Constructor Summary
ConstructorsConstructorDescriptionSessions()Default settings and an in-memory store, for a server with no generated application. -
Method Summary
Modifier and TypeMethodDescriptionstatic Sessionsconfigure(Config config, boolean tls, DataSource pool, Backend.Application application) Readscn1.session.*into a server's session settings.The name of the session cookie.getStore()The store sessions are kept in.voidsetStore(SessionStore replacement) Replaces the store, for one of the application's own -- before the first request uses a session.
-
Constructor Details
-
Sessions
public Sessions()Default settings and an in-memory store, for a server with no generated application.
-
-
Method Details
-
configure
public static Sessions configure(Config config, boolean tls, DataSource pool, Backend.Application application) throws IOException Reads
cn1.session.*into a server's session settings. Called by the server when it starts; every server has its own, because cookies are not scoped by port and a client of two servers on one host would otherwise present one server's session to the other.Parameters
-
tls: whether the server terminates TLS, forsecure=auto -
pool: the database, forstore=db -
application: destroys the session-scoped beans, or null
- Throws:
IOException
-
-
setStore
Replaces the store, for one of the application's own -- before the first request uses a session. A server hands out sessions from the moment it listens, so a store set later would lose the ones already in the old store, cookies and beans alike;
Backend.Builder.sessionStoreinstalls one before the listener binds.Throws
IllegalStateException: once a session has been looked up
-
getStore
The store sessions are kept in. -
getCookieName
The name of the session cookie.
-