629 Commits (4.1.x)

Author SHA1 Message Date
Rob Winch ccf96a4d69 SEC-2542: Polish dependency exclusions 12 years ago
Rob Winch 3118e39de8 SEC-2542: Use exclusions to remove duplicate dependencies 12 years ago
Rob Winch c0590e614a SEC-2177: Polish 12 years ago
Maciej Zasada 7cf37856c0 SEC-2177: Striping off all leading schemes 12 years ago
Julien Dubois 7325b97c76 SEC-2519: RememberMeAuthenticationException supports root cause 12 years ago
Rob Winch ea902e5829 SEC-2507: WebExpressionVoter.supports support subclasses of FilterInvocation 12 years ago
Rob Winch e15cee62f4 SEC-2511: Remove double ALLOW-FROM in X-Frame-Options header 12 years ago
getvictor 6de138c2f2 SEC-2511: Remove double ALLOW-FROM from X-Frame-Options header. 12 years ago
Rob Winch 9988fa141c Update Spring Security version in pom.xml 12 years ago
Rob Winch 6be4e3a9fc SEC-2506: Remove Bundlor Support 12 years ago
Rob Winch 7f99a2dfbb SEC-2487: Update to Spring 3.2.8.RELEASE 12 years ago
Rob Winch ec8b48150d SEC-2474: Update poms 12 years ago
Rob Winch 8d8475deb1 SEC-2455: form-login@login-processing-url & logout@logout-url use matchers 12 years ago
Rob Winch 2df5541905 SEC-2448: Update to HSQL 2.3.1 12 years ago
Rob Winch ca1080fb96 SEC-2439: HttpSessionCsrfTokenRepository setHeaderName sets header instead of parameter 12 years ago
Rob Winch a34178bc40 SEC-2434: Update to Spring 3.2.6 and Spring 4.0 GA 12 years ago
Rob Winch aaa7cec32e SEC-2326: CsrfRequestDataValueProcessor implements RequestDataValueProcessor 12 years ago
Rob Winch 7f714ebb23 SEC-2422: Session timeout detection with CSRF protection 12 years ago
Rob Winch 4460e84b29 Updates to pom.xml author and repo 12 years ago
David Alberto f9998d582a Correct typo in AbstractRememberMeServices assertion 12 years ago
Rob Winch 59e13e7bbb SEC-2404: CsrfAuthenticationStrategy creates new valid CsrfToken 12 years ago
Rob Winch 2c8946c406 Next development version 12 years ago
Spring Buildmaster 9c703a3051 Release version 3.2.0.RC2 12 years ago
Rob Winch 1a1f577a8b SEC-2358: Add RequestHEaderRequestMatcher#toString() 12 years ago
Rob Winch e638f0a547 SEC-2357: old RequestMatcher interface extends new RequestMatcher 12 years ago
Rob Winch 04b091c385 SEC-2369: PreAuthenticatedGrantedAuthoritiesUserDetailsService fix case to createUserDetails method 12 years ago
Rob Winch 15a63c58a7 SEC-2368: DebugFilter outputs headers and HTTP method 12 years ago
Rob Winch 1351c8bada SEC-2362: Clarify AbstractRememberMeServices loginSuccess javadoc 12 years ago
Adrien be e50b587d60 SEC-2360: AbstractRememberMeServices provide message for Assert on key fieldd 12 years ago
Rob Winch 0b0e7dbea9 SEC-2359: Merge DefaultLoginPageViewFilter w/ DefaultLoginPageGeneratingFilter 12 years ago
Rob Winch 51171efa7a SEC-2357: Move *RequestMatcher to .matcher package 12 years ago
Rob Winch 45ad74a0bd SEC-2357: Fix package cycles 12 years ago
Rob Winch 14b9050616 SEC-2357: Move *RequestMatchers to .matchers package 12 years ago
Rob Winch 7d99436740 SEC-2358: Add RequestHeaderRequestMatcher 12 years ago
Rob Winch 0ac1176152 Polish RequestMatcher logging and toString 12 years ago
Rob Winch cffbefadd1 SEC-2306: Fix Session Fixation logging race condition 12 years ago
kazuki43zoo 611a97023d SEC-2352: HttpSessionCsrfTokenRepository lazy session creation 12 years ago
Rob Winch 17efd25717 SEC-2331: Include Expires: 0 in security headers documentation 12 years ago
Rob Winch cea0cf9260 SEC-2243: Remove additional Debug Filter 12 years ago
Rob Winch b591881e95 SEC-2302: Provide beforeSpringSecurityFilterChain hook 12 years ago
Rob Winch 88f41cdf62 SEC-2341: Update to Gradle 1.8 12 years ago
Rob Winch ddc0ef7ab3 SEC-2339: Added Logical (Or, And, Negated) RequestMatchers 12 years ago
Rob Winch 788ba9a1fa SEC-2329: Allow injecting of AuthenticationTrustResolver 12 years ago
Rob Winch 9133c33f1d SEC-2246: HttpSessionRequestCache.getRequest casts to RequestCache 12 years ago
Rob Winch 8f8c6169e8 SEC-2331: Cache Control now includes Expires: 0 12 years ago
Rob Winch 0114b457c0 SEC-2330: CacheControlHeadersWriter use a single header 12 years ago
Rob Winch 32e9239fd2 SEC-2320: AuthenticationPrincipal can be null on invalid type 12 years ago
Rob Winch b22acd0768 SEC-2314: AbstractSecurityWebApplicationInitializer.getSessionTrackingModes() uses EnumSet 12 years ago
Rob Winch 8e74407381 SEC-2296: HttpServletRequest.login should throw ServletException if already authenticated 13 years ago
Rob Winch e8ac11641b SEC-2297: Add DispatchType.ASYNC as default for AbstractSecurityWebApplicationInitializer 13 years ago