Spring Buildmaster
0e9d9da46b
Release version 4.0.4.RELEASE
10 years ago
Kazuki Shimizu
675ac80926
SEC-3147: Add error parameter for default authentication-failure-url
10 years ago
Rob Winch
5f6e3855f1
Next Development Version
10 years ago
Spring Buildmaster
19f88e9179
Release version 4.0.3.RELEASE
10 years ago
Rob Winch
cf9b6bc0de
SEC-2848: LogoutConfigurer allows setting clearAuthentication
10 years ago
Rob Winch
fc67550ff2
SEC-3135: antMatchers(<method>,new String[0]) now passive
10 years ago
Rob Winch
8663ac4173
SEC-3135: antMatchers now allows method and no pattern
...
Previously, antMatchers(POST).authenticated() was not allowed. Instead
users had to use antMatchers(POST, "/**").authenticated().
Now we default the patterns to be "/**" if it is null or empty.
10 years ago
Rob Winch
b719e0fbcc
SEC-3132: securityBuilder cannot be null
...
If a custom SecurityConfiguererAdapter applies another
SecurityConfigurerAdapter it caused an error securityBuilder cannot be null.
This commit fixes this.
10 years ago
Rob Winch
7074daac0e
SEC-3063: rm ConditionalOnMissingBean for @Primary
...
ConditionalOnMissingBean can only work in a Spring Boot environment. This
means this approach is flawed.
Instead users that wish to override requestDataValueProcessor can use
@Primary .
10 years ago
Rob Winch
41c9431fcc
Test that form log in requires CSRF
11 years ago
Rob Winch
453e6332da
Fix indentation of CsrfConfigTests
11 years ago
Rob Winch
969f3a7d1b
Update pom.xml to latest snapshots
11 years ago
Thomas Darimont
ad1d858e2b
SEC-3056 - Fix JavaDoc errors.
...
Fixed JavaDoc errors accross multiple modules in order to make javadoc happy with Java 8.
11 years ago
Rob Winch
dab4cf18b8
SEC-3032: Correct documented logout-success-url default
11 years ago
Rob Winch
e8c9f75f9c
Update pom.xml to latest versions
11 years ago
Rob Winch
07fb2af74b
SEC-3011: AbstractUrlAuthorizationConfigurer postProcess default AccessDecisionManager
11 years ago
Rob Winch
ab1b7a1eb6
Remove unnecessary @SuppressWarnings
11 years ago
Rob Winch
9654df2cc3
SEC-3045: Conditionally add MethodSecurityMetadataSourceAdvisor
11 years ago
Rob Winch
a3df41b380
Clean Import Statements
11 years ago
Rob Winch
0e36f85dab
SEC-3019: Java Config for Http Basic supports Rememberme
11 years ago
Rob Winch
474d624e8e
SEC-2988: Renamed OnBeanCondition.java to OnMissingBeanCondition.java
11 years ago
Rob Winch
64938ebcfc
SEC-2996: Suport configuring SecurityExpressionHandler<Message<Object>>
11 years ago
Stijn
ca0ffb8b5d
SEC-2948: Fix error message for wrong xsd schema
...
When using the wrong xsd schema < 4.0 a message was shown that the
schema needed to be version 3.2.
In reality this schema had to be version 4.0.
11 years ago
Rob Winch
1f74ac811e
Fix Spring IO Tests
11 years ago
Rob Winch
197ddb3cd1
SEC-3029: Fix Compatibility with Spring 4.2.x
11 years ago
Alex Panchenko
0a118336d4
SEC-2955: Convert to "static" for inner classes
11 years ago
Rob Winch
f1352ba492
SEC-2942: Add test EnableWebSecurity supports AuthenticationPrincipal
11 years ago
Rob Winch
f548d89b27
SEC-2932: SecurityContextConfigurer defaults SecurityContextRepository
11 years ago
Rob Winch
09acc2b7a5
SEC-2962: SecurityContextHolderAwareRequestFilter default rolePrefix
11 years ago
Rob Winch
38e2e23b86
Fix indentation of InterceptUrlConfigTests
11 years ago
Rob Winch
d5dfeeca49
SEC-2927: Update chat-jc pom so Maven Builds
...
Previously there were some incorrect dependency versions. This commit fixes
that.
We added dependencyManagement for Spring Framework and corrected
Thymeleaf and embedded redis versions.
11 years ago
Rob Winch
0bfbd2923a
SEC-2915: Fix defaut login page tests with tabs
11 years ago
Rob Winch
4fdfb8caba
SEC-2915: More Tabs -> Spaces
11 years ago
Rob Winch
5fa5630bc3
Polish ordering of Config and test in NamespaceRememberMeTests
...
The convention is to put the config just below the test.
This commit fixes the convention for NamespaceRememberMeTests
11 years ago
Kazuki Shimizu
0c77c2071b
SEC-2880: Add a setter method to override the cookie name of remember-me
11 years ago
Rob Winch
ec89fdcfaa
SEC-2919: Polish
...
Remove now unnecessary AuthenticationConfig.Builder#getLoginFormUrl
method.
11 years ago
Rob Winch
052bd32f40
SEC-2919: DefaultLoginPageGeneratingFilter disabled when login-page specified
11 years ago
Rob Winch
4ca936bb76
SEC-2913: Polish
11 years ago
Rob Winch
6c541468f6
SEC-2913: Post Process default session fixation AuthenticationStrategy
...
Before the default session fixation AuthenticationStrategy used a
NullEventPublisher when using the Java Configuration. This was due to the
fact that it is not exposed as a Bean and is not post processed.
We now post process the default session fixation AuthenticationStrategy
which initializes the EventPublisher properly.
11 years ago
Rob Winch
7b25b3e40d
SEC-2864: Default Spring Security WebSocket PathMatcher XML Namespace
11 years ago
Rob Winch
db531d9100
SEC-2917: Update to Spring 4.1.6
11 years ago
Rob Winch
57b06fb0b5
SEC-2864: Default Spring Security WebSocket PathMatcher
11 years ago
Rob Winch
c94a5cf8e2
SEC-2916: disable-url-rewriting=true by default
11 years ago
Rob Winch
ae6af5d73c
SEC-2915: Updated Java Code Formatting
11 years ago
Rob Winch
0a2e496a84
SEC-2915: groovy/gradle spaces->tabs
11 years ago
Rob Winch
cf9f58a4ac
SEC-2915: XML spaces->tabs
11 years ago
Rob Winch
fbf3672eca
SEC-2908: mulitple invocations of http.requetMatchers() properly chains
11 years ago
Rob Winch
e776a1fd35
SEC-2803: Add HttpStatusEntryPoint
11 years ago
Rob Winch
bed20db905
Remove Unnecessary @Override
11 years ago
Romain Fromi
8b78194f31
SEC-2876: HttpSecurityBuilder addFilterAfter javadoc before->after
11 years ago