org.springframework.security.web.authentication.rememberme.CookieTheftException: Invalid remember-me token (Series/token) mismatch. Implies previous cookie theft attack.
at org.springframework.security.web.authentication.rememberme.PersistentTokenBasedRememberMeServices.processAutoLoginCookie(PersistentTokenBasedRememberMeServices.java:102)
at org.springframework.security.web.authentication.rememberme.AbstractRememberMeServices.autoLogin(AbstractRememberMeServices.java:115)
我注意到的是该processAutoLoginCookie
方法被调用了两次。方法本身的行为似乎是正确的,例如,更新数据库中的令牌和更新客户端中的 cookie。对此的任何帮助将不胜感激。