Rob Winch
7f54c8b8b4
Fix link to CSP in Reference Doc
...
Previously the link in the reference from x-frame-options to the
content security policy section was broken.
This commit fixes the link.
Issue gh-4063
9 years ago
Fred Cooke
12173c04ee
Fix Typo in Reference Docs
...
Word substitution, it's foolproof, not full proof :-)
Fixes gh-4063
9 years ago
Marten Deinum
b88418b94a
Configuration of session management strategies
...
This commit adds an ExpiredSessionStrategy for the ConcurrentSessionFilter
analogous to the InvalidSessionStrategy for the SessionManagementFilter. It also
adds a configuration option for both the InvalidSessionStrategy and
ExpiredSessionStrategy to the XML namespace and Java configuration.
Fixes gh-3794
Fixes gh-3795
9 years ago
Kazuki Shimizu
37c6605062
Add explanation for DelegatingAuthenticationFailureHandler ( #207 )
9 years ago
Marek Jeszka
2deb722a1f
JavaDoc links in 5.5 Handling Logouts fixed ( #3993 )
...
Fixes gh-3992
9 years ago
qwazer
fe117bc445
[minor] fix grammar error ( #4013 )
...
add space: that"collects" -> that "collects"
9 years ago
Rob Winch
3befb1c8a6
MvcRequestMatcher servletPath / JavaConfig
...
Issue: gh-3987
9 years ago
Artur Owczarek
0b14664a8c
Fix typos in reference ( #3979 )
10 years ago
Johnny Lim
69306a8b46
Fix typo ( #3968 )
...
Fixes typo `advantadge`
10 years ago
Johnny Lim
310bb39a0d
Fix typo
10 years ago
Rob Winch
e4c13e3c0e
Add MvcRequestMatcher
...
Fixes gh-3964
10 years ago
Rob Winch
13bc70f693
Add CorsFilter support
10 years ago
Rob Winch
dd9b59ba31
Document Digest is insecure
...
Fixes gh-3894
10 years ago
Shannon Carey
9fa2c64737
Documentation SecurityConfig->WebSecurityConfig
...
Rename SecurityConfig to WebSecurityConfig in the documentation.
Fixes gh-153
10 years ago
Pedro Vilaça
208f898403
Improve csrf login caveats
...
Add a suggestion to retrieve a fresh csrf token right before the
form submission in order to avoid problems with invalid csrf tokens
due session timeouts.
Fixes gh-3925
10 years ago
Ryan W. Moore
8aea83011d
Docs: Remove broken link
...
I think the originally intended destination no longer exists in the
documentation.
10 years ago
Ryan W. Moore
fd65652bbe
Docs: Fix broken link to security database schema
10 years ago
Ryan W. Moore
38e9f6a851
Docs: Fix broken link to csrfInput tag info
...
ID names are case sensitive.
10 years ago
Ryan W. Moore
cdb04c50e8
Docs: Fix broken link to websocket security info
10 years ago
Ryan W. Moore
057ea4fb17
Docs: Make 'Getting Started' a level 1 section heading
...
This fixes the following build error:
asciidoctor: ERROR: index.adoc: line 26: invalid part, must have at least one
section (e.g., chapter, appendix, etc.)
10 years ago
David Kane
503828c994
Add FAQ for JSP taglib & method security
...
Updated FAQ to clarify how the url attribute of the authorize tag
interacts with method security
10 years ago
Pedro Vilaça
ea2b5dd412
Fix wrong class name reference in the docs
...
In the documentation, there was a reference to a class called CsrfTokenResolver
and it should CsrfTokenArgumentResolver
Fixes gh-3890
10 years ago
Rob Winch
f363c62afd
Document spring-security-test dependency
...
Fixes gh-3873
10 years ago
Joe Grandja
66980e827c
Add Spring Boot Hello World guide
...
Add Spring Boot Hello World Guide
Fixes gh-3866
10 years ago
Rob Winch
ede521dc8d
authorizeUrls -> authorizeRequests
...
Replace remaining authorizeUrls with authorizeRequests
Fixes gh-3875
10 years ago
Rob Winch
d4218c70f1
Update CookieCsrfTokenRepository docs to cookiHttpOnly=false
...
Currently CookieCsrfTokenRepository does not specify that the httpOnly
flag needs set to false. We should update the reference to include this
setting (and a comment about it) since it states that the settings will
work with AngularJS.
This commit updates the documentation and provides a convenience factory
method to create a CookieCsrfTokenRepository with cookiHttpOnly=false
Fixes gh-3865
10 years ago
Rob Winch
9745de9510
Add @AuthenticationPrincipal expression
...
It is now possible to provide a SpEL expression for
@AuthenticationPrincipal . This allows invoking custom logic including
methods on the principal object.
Fixes gh-3859
10 years ago
Patrick Cornelißen
eaf8729941
Fixes RC1/RC2 URLs
...
Fixes gh-3838
10 years ago
Wim Deblauwe
85786824af
Fix logout url in doc
...
The default for logout is to redirect to `/login?logout`
Fixes gh-251
10 years ago
Joe Grandja
4ee46a5f58
Add What's new in 4.1 RC2
...
Add What's new in 4.1 RC2
Fixes gh-3830
10 years ago
Johnny Lim
933a7e8363
Remove duplicate words
...
Fixes gh-3826
10 years ago
Joe Grandja
81c9fa805f
Fix AuthenticationPrincipalArgumentResolver xml doc
...
Fixes gh-3771
10 years ago
Joe Grandja
2ef3da1b47
Documents the new @AuthenticationPrincipal in more detail.
...
Fixes gh-3771
10 years ago
Rob Winch
95a3e30d9f
Polish Pbkdf2PasswordEncoder
...
Fixes gh-2158
Fixes gh-51
10 years ago
Rob Winch
d3a9cc6eae
Add CsrfTokenRepository ( #3805 )
...
* Create LazyCsrfTokenRepository
Fixes gh-3790
* Add CookieCsrfTokenRepository
Fixes gh-3009
10 years ago
Art O Cathain
1d271184c9
Fix Documentation Formatting
...
Fix corrupted character and add formatting per the duplicated text
block
Fixes gh-193
10 years ago
Soeun Park
8f7cf28435
Fix typos in documentation
...
Fixes gh-196
Fixes gh-3109
10 years ago
Johnny Lim
fe94d654ed
Fix typos ( #228 )
10 years ago
Joe Grandja
945a21a3fb
Use xml / javaconfig folders for samples
...
Fixes gh-3752
10 years ago
Kamill Sokol
9c3db557dd
Add missing # in SpEL expression doc
...
SpEL variables can be referenced in the expression using the syntax
23.2.2 Path Variables in Web Security Expressions.
Fixes gh-3781
10 years ago
Joe Grandja
9e5cdbd133
Includes a reference to the https://report-uri.io/ service in the CSP and HPKP documentation.
...
Fixes gh-3772
10 years ago
Rob Winch
b3d26ed5d6
Add changelog in What's New
...
Issue gh-3768
10 years ago
Rob Winch
bf9a837b9a
Polish What's New
...
Issue gh-3768
10 years ago
Rob Winch
40b7fa5b72
Update Issues Link
...
Issue gh-3333
10 years ago
Rob Winch
3e47531b19
Polish CSP reference
...
Issue gh-3763
10 years ago
Rob Winch
e04f685747
Fix Typo in @WithUserDetails reference
...
Issue gh-3346
10 years ago
Joe Grandja
2f7f2ff589
Adds support for Content Security Policy
...
Fixes gh-2342
10 years ago
Rob Winch
4cb9b202f8
Remove subversion from reference
...
Fixes gh-3766
10 years ago
Rob Winch
683d751902
Polish What's New
...
Fixes gh-3768
10 years ago
Rob Winch
4b650dc58d
Allow AuthenticationProvider Bean in Java Config
...
This commit adds support for defaulting java configuration's
authentication by providing an AuthenticationProvider Bean.
Fixes gh-3091
10 years ago