skip to content

Remember-Me

Remember-me issues a long-lived cookie, either a signed hash or a persistent series-and-token pair in a table, with quite different theft-detection properties. Interviewers ask which is safer and why the persistent form can spot a stolen cookie.

part ofSpring Frameworkoverview, primer and where to startread it →
on this pageshow

questions

5

Compare PersistentTokenBasedRememberMeServices with TokenBasedRememberMeServices. When would you choose persistent tokens?

level: seniorimportance: must knowfreq 50%

basics

~20 s

TokenBased is a stateless signed cookie with no storage but no per-device revocation. Persistent stores a series/token row per login in a database, rotates the token on each use, allows revoking single devices, and can detect a stolen (cloned) cookie. Choose persistent when you need revocation and theft detection.

open as a page

What is the 'remember-me' feature in Spring Security, and how do you enable it?

level: juniorimportance: should knowfreq 45%

basics

~10 s

Remember-me keeps a user logged in across browser restarts by sending a long-lived cookie instead of relying only on the session. You enable it with the rememberMe() method in the SecurityFilterChain configuration.

open as a page

Where does RememberMeAuthenticationFilter sit in the filter chain, and how does it turn a cookie into an authenticated user?

level: seniorimportance: should knowfreq 40%

basics

~20 s

RememberMeAuthenticationFilter runs late in the chain, after normal login filters but before the anonymous filter. If no user is already authenticated, it reads the remember-me cookie via RememberMeServices.autoLogin(), and if valid it authenticates a RememberMeAuthenticationToken through the AuthenticationManager and stores it in the SecurityContext.

open as a page

You're designing remember-me for a security-sensitive production app. What are the key risks and how do you harden the configuration?

level: principalimportance: should knowfreq 30%

basics

~20 s

The core risk is a stolen long-lived cookie granting account access. Harden by serving only over HTTPS with Secure and HttpOnly cookies, using persistent tokens for revocation and theft detection, keeping validity short, setting a stable secret key, and gating sensitive actions behind fullyAuthenticated so remember-me users must re-enter their password.

open as a page