Rob Winch
cfc057b629
StrictHttpFirewall allows CJKV characters
...
Closes gh-11264
4 years ago
Rob Winch
d94639a1bb
StrictHttpFirewall allows CJKV characters
...
Closes gh-11264
4 years ago
Rob Winch
0dcb592b03
AntRegexRequestMatcher Optimization
...
Closes gh-11234
4 years ago
Rob Winch
0ece0e6012
Extract rejectNonPrintableAsciiCharactersInFieldName
...
Closes gh-11234
4 years ago
Rob Winch
7f121e82f4
AntRegexRequestMatcher Optimization
...
Closes gh-11234
4 years ago
Rob Winch
9059fb3fc7
Extract rejectNonPrintableAsciiCharactersInFieldName
...
Closes gh-11234
4 years ago
Eleftheria Stein
3389cf3ffc
Revert "Lock dependencies"
...
This reverts commit 83bb4603f8 .
4 years ago
Eleftheria Stein
83bb4603f8
Lock dependencies
4 years ago
Steve Riesenberg
65b3584ac6
Update copyright year
...
Issue gh-10557
4 years ago
Steve Riesenberg
fa5b8c6090
Update copyright year
...
Issue gh-10557
4 years ago
Steve Riesenberg
1d814f95d5
Fix case sensitive headers comparison
...
Closes gh-10557
4 years ago
Steve Riesenberg
3aa2a60f97
Fix case sensitive headers comparison
...
Closes gh-10557
4 years ago
Marcus Da Coregio
01be7eca6e
Improve log message when no CSRF token found
...
Closes gh-10436
4 years ago
Marcus Da Coregio
5a47e17a0d
Improve log message when no CSRF token found
...
Closes gh-10436
4 years ago
Josh Cummings
21f0ccd088
Restructure SwitchUserFilter Logs
...
Issue gh-6311
4 years ago
Joe Grandja
5c8cd23a2d
Revert "Lock dependencies"
...
This reverts commit fc53f81d2e .
4 years ago
Josh Cummings
9481122e02
Restructure SwitchUserFilter Logs
...
Issue gh-6311
4 years ago
Eleftheria Stein
fc53f81d2e
Lock dependencies
4 years ago
Marcus Da Coregio
c706a103f9
Revert "Lock Dependencies"
...
This reverts commit 1533f098d2 .
4 years ago
Marcus Da Coregio
1533f098d2
Lock Dependencies
4 years ago
Marcus Da Coregio
b0d22d1a03
Revert "Lock Dependencies"
...
This reverts commit eb300c78bd .
5 years ago
Marcus Da Coregio
eb300c78bd
Lock Dependencies
5 years ago
Marcus Hert da Coregio
02285708eb
Adjust createNewSessionIfAllowed to prevent NPE
...
Ensure that isTransientAuthentication reuses the same authentication object from saveContext
Closes gh-8947
5 years ago
Craig Andrews
ab34c0308c
Add guard around logger.debug statement
...
The log message involves string concatenation, the cost of which
should only be incurred if debug logging is enabled
Issue gh-9648
5 years ago
Craig Andrews
a85ce9c91f
Add guard around logger.debug statement
...
The log message involves string concatenation, the cost of which
should only be incurred if debug logging is enabled
Issue gh-9648
5 years ago
Joe Grandja
26c6570b10
Revert "Lock Dependencies"
...
This reverts commit b3250c06a9 .
5 years ago
Joe Grandja
b3250c06a9
Lock Dependencies
5 years ago
佚名
8dc702c80f
Add null check in CsrfFilter and CsrfWebFilter
...
Solve the problem that CsrfFilter and CsrfWebFilter
throws NPE exception when comparing two byte array
is equal in low JDK version.
When JDK version is lower than 1.8.0_45, method
java.security.MessageDigest#isEqual does not verify
whether the two arrays are null. And the above two
class call this method without null judgment.
ZiQiang Zhao<1694392889@qq.com>
Closes gh-9561
5 years ago
佚名
22d7043d01
Add null check in CsrfFilter and CsrfWebFilter
...
Solve the problem that CsrfFilter and CsrfWebFilter
throws NPE exception when comparing two byte array
is equal in low JDK version.
When JDK version is lower than 1.8.0_45, method
java.security.MessageDigest#isEqual does not verify
whether the two arrays are null. And the above two
class call this method without null judgment.
ZiQiang Zhao<1694392889@qq.com>
Closes gh-9561
5 years ago
Rob Winch
71f9876c48
Revert "Lock dependencies"
...
This reverts commit dca4858d81 .
5 years ago
Rob Winch
dca4858d81
Lock dependencies
5 years ago
Rob Winch
419839d05c
Optimize HttpSessionSecurityContextRepository
...
Closes gh-9387
5 years ago
Rob Winch
38e9e8ca52
Optimize HttpSessionSecurityContextRepository
...
Closes gh-9387
5 years ago
Rob Winch
e2121532a2
Optimize HttpSessionSecurityContextRepository
...
Closes gh-9387
5 years ago
Rob Winch
7cab7b06c5
Optimize HttpSessionSecurityContextRepository
...
Closes gh-9387
5 years ago
Rob Winch
ec8f6014d4
Revert "Lock dependencies"
...
This reverts commit fa5f789beb .
5 years ago
Rob Winch
fa5f789beb
Lock dependencies
5 years ago
Josh Cummings
68ac3ef36b
Polish Tests
...
Issue gh-9331
5 years ago
happier233
7a5c34ca57
Configure CurrentSecurityContextArgumentResolver BeanResolver
...
Closes gh-9331
5 years ago
Josh Cummings
10946e8153
Polish Tests
...
Issue gh-9331
5 years ago
happier233
3cb98ebed0
Configure CurrentSecurityContextArgumentResolver BeanResolver
...
Closes gh-9331
5 years ago
Rob Winch
1181740f79
Constant Time Comparison for CSRF tokens
...
Closes gh-9291
5 years ago
Rob Winch
e6d6b39767
Constant Time Comparison for CSRF tokens
...
Closes gh-9291
5 years ago
Rob Winch
628ea00ad4
Fix CsrfWebFilter error message when expected CSRF not found
...
Closes gh-9337
5 years ago
Rob Winch
b08075a721
Fix CsrfWebFilter error message when expected CSRF not found
...
Closes gh-9337
5 years ago
Josh Cummings
7c2010f507
Revert "Lock Dependencies for 5.3.6"
...
This reverts commit a153012056 .
5 years ago
Josh Cummings
a153012056
Lock Dependencies for 5.3.6
5 years ago
Josh Cummings
2dcfda7fac
Revert "Lock Dependencies for 5.3.5.RELEASE"
...
This reverts commit 846a5a962c .
5 years ago
Josh Cummings
846a5a962c
Lock Dependencies for 5.3.5.RELEASE
5 years ago
Tomoki Tsubaki
85889d5e0b
Create the CSRF token on the bounded elactic scheduler
...
The CSRF token is generated by UUID.randomUUID() which is I/O blocking operation.
This commit changes the subscriber thread to the bounded elactic scheduler.
Closes gh-9018
5 years ago