diff --git a/core/src/main/java/org/springframework/security/intercept/web/FilterInvocationDefinitionSourceMapping.java b/core/src/main/java/org/springframework/security/intercept/web/FilterInvocationDefinitionSourceMapping.java index 1751dfd0ac..dfa7613fe1 100644 --- a/core/src/main/java/org/springframework/security/intercept/web/FilterInvocationDefinitionSourceMapping.java +++ b/core/src/main/java/org/springframework/security/intercept/web/FilterInvocationDefinitionSourceMapping.java @@ -29,7 +29,7 @@ import org.springframework.security.ConfigAttribute; * @version $Id$ * @since 1.1 */ -public class FilterInvocationDefinitionSourceMapping { +class FilterInvocationDefinitionSourceMapping { private String url; diff --git a/core/src/main/java/org/springframework/security/intercept/web/PathBasedFilterInvocationDefinitionMap.java b/core/src/main/java/org/springframework/security/intercept/web/PathBasedFilterInvocationDefinitionMap.java index 874ffc7f42..f9bd6fd6f4 100644 --- a/core/src/main/java/org/springframework/security/intercept/web/PathBasedFilterInvocationDefinitionMap.java +++ b/core/src/main/java/org/springframework/security/intercept/web/PathBasedFilterInvocationDefinitionMap.java @@ -54,6 +54,9 @@ public class PathBasedFilterInvocationDefinitionMap extends DefaultFilterInvocat public void addSecureUrl(String antPath, String method, ConfigAttributeDefinition attr) { // SEC-501: If using lower case comparison, we should convert the paths to lower case // as any upper case characters included by mistake will prevent the URL from ever being matched. + // This shouldn't be needed anymore. The property editor complains if there is upper case text in the URL + // and the namespace implementation does the conversion itself, so it is safe to use the parent class + // directly. if (getUrlMatcher().requiresLowerCaseUrl()) { antPath = antPath.toLowerCase(); }