Shiro: how do I remember how I work?

I have a few questions about Shiro that remember me:

  • Why does Shiro generate different “remember me” tokens for the same account every time I log in?
  • Can a hacker generate a “remember me” token for any account, if I use the default CipherKey?
  • How can I control the “remember me” duration? Liver by age? So, if the client cookie never expires, then remember me cookie will work forever?
+4
source share
2 answers

" " , , . . , .

Shiro

Shiro :

+5
  • .
  • BalusC. .
  • rememberMe cookie - . Shiro cookie rememberMeManager:

    securityManager.rememberMeManager.cookie.maxAge = <max_age >

+1

All Articles