Class Sessions

java.lang.Object
com.codename1.backend.Sessions

public final class Sessions extends Object

How a server keeps HttpSessions: the cookie, the lifetime and the store, read from configuration when the server starts.

  cn1.session.cookie=CN1SESSION      # the cookie's name
  cn1.session.timeout=1800           # seconds of inactivity, 0 for never
  cn1.session.store=memory           # or db
  cn1.session.same-site=Lax          # Lax, Strict or None
  cn1.session.secure=auto            # true, false, or auto (on under TLS)

Nothing here runs for a request that does not ask for its session: the cookie is parsed on the first getSession, and a request that never calls it costs one field check when it ends.

  • Nested Class Summary

    Nested Classes
    Modifier and Type
    Class
    Description
    static final class 
    Sessions in the server's database, in cn1_http_session, so every instance of a server sees every session.
    static final class 
    Sessions in this process's memory.
  • Constructor Summary

    Constructors
    Constructor
    Description
    Default settings and an in-memory store, for a server with no generated application.
  • Method Summary

    Modifier and Type
    Method
    Description
    static Sessions
    configure(Config config, boolean tls, DataSource pool, Backend.Application application)
    Reads cn1.session.* into a server's session settings.
    The name of the session cookie.
    The store sessions are kept in.
    void
    setStore(SessionStore replacement)
    Replaces the store, for one of the application's own -- before the first request uses a session.

    Methods inherited from class Object

    clone, equals, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
  • Constructor Details

    • Sessions

      public Sessions()
      Default settings and an in-memory store, for a server with no generated application.
  • Method Details

    • configure

      public static Sessions configure(Config config, boolean tls, DataSource pool, Backend.Application application) throws IOException

      Reads cn1.session.* into a server's session settings. Called by the server when it starts; every server has its own, because cookies are not scoped by port and a client of two servers on one host would otherwise present one server's session to the other.

      Parameters
      • tls: whether the server terminates TLS, for secure=auto

      • pool: the database, for store=db

      • application: destroys the session-scoped beans, or null

      Throws:
      IOException
    • setStore

      public void setStore(SessionStore replacement)

      Replaces the store, for one of the application's own -- before the first request uses a session. A server hands out sessions from the moment it listens, so a store set later would lose the ones already in the old store, cookies and beans alike; Backend.Builder.sessionStore installs one before the listener binds.

      Throws
      • IllegalStateException: once a session has been looked up
    • getStore

      public SessionStore getStore()
      The store sessions are kept in.
    • getCookieName

      public String getCookieName()
      The name of the session cookie.