Class ExpirableResponseCookie

Object
se.curity.identityserver.sdk.web.cookie.ResponseCookie
se.curity.identityserver.sdk.web.cookie.ExpirableResponseCookie
All Implemented Interfaces:
Cookie

public final class ExpirableResponseCookie extends ResponseCookie
A HTTP Cookie that can expire with or without being persisted on the client-side.

The main difference from StandardResponseCookie is that this type of cookie separates persistence and max-age into different, independent concepts.

In other words, a ExpirableResponseCookie may expire within a pre-defined amount of time without having to be persisted by the client.

To achieve that, the max-age of the cookie is encoded within the value of the cookie. For this reason, only signed and encrypted cookies may be of this type, as otherwise there would be no way to safely encode the max-age in the cookie's plain-text value.

Since:
2.1.0
  • Constructor Details

    • ExpirableResponseCookie

      public ExpirableResponseCookie(String name, @Nullable String value, Duration maxAge, boolean isPersistent)
      Create a ExpirableResponseCookie instance.
      Parameters:
      name - of the cookie
      value - of the cookie
      maxAge - the cookie should be valid for
      isPersistent - whether or not this cookie should be persisted in the client
    • ExpirableResponseCookie

      public ExpirableResponseCookie(Cookie cookie, Duration maxAge, boolean isPersistent)
      Create a copy of the given cookie.
      Parameters:
      cookie - to be copied
      maxAge - maximum age of the cookie
      isPersistent - whether or not this cookie should be persisted in the client
  • Method Details

    • getMaxAge

      public Duration getMaxAge()
      Returns:
      the maximum age of this cookie.

      This is the same as the max-age attribute of the cookie if the cookie is persistent.

    • isPersistent

      public boolean isPersistent()
      Returns:
      whether or not this cookie should be persisted by the client.
    • setMaxAge

      public void setMaxAge(Duration maxAge)
      Set the maximum age of this cookie.

      This is the same as the max-age attribute of the cookie if the cookie is persistent.

      Parameters:
      maxAge - maximum age of the cookie
    • setPersistent

      public void setPersistent(boolean persistent)
      Set whether or not this cookie should be persisted by the client.
      Parameters:
      persistent - whether or not this cookie should be persisted in the client