Joe Grandja
0eaffb37e7
Require Locale argument for toLower/toUpperCase usage
1 year ago
Rob Winch
4ce7cde155
Add Firewall for WebFlux
...
Closes gh-15967
1 year ago
Marcus Da Coregio
7813a9ba26
Use default PathPatternParser instance
2 years ago
Christoph Zuleger
06e58e4c34
Update JavaDoc of BasicAuthenticationFilter
...
Remove deprecated hint to use Digest Auth in favor of Basic Auth.
3 years ago
Marcus Da Coregio
a53cbb838b
Polish
...
Issue gh-13155
3 years ago
joerg-richter-5234
8287289bcb
Fix XContentTypeOptionsServerHttpHeadersWriter
...
set constant value to X-Content-Type-Options
Closes gh-13155
3 years ago
Marcus Da Coregio
2d52fb8e4b
Clear Repository on Logout
3 years ago
Christian Marck
442faccb5f
Avoid NPE in FilterInvocation
...
Handle unknown headers in dummy request wrapper.
Closes gh-12998
3 years ago
twosom
3d7e22a4e9
Add test to SimpleUrlAuthenticationSuccessHandlerTests
3 years ago
Marcus Da Coregio
84cca81edf
Use HttpSessionSecurityContextRepository by default in SwitchUserFilter
...
Closes gh-12834
3 years ago
Marcus Da Coregio
ffdb397830
Save the SecurityContext when switching user
...
Closes gh-12504
3 years ago
Marcus Da Coregio
1f481aafff
Fix AuthorizationFilter incorrectly extending OncePerRequestFilter
...
Closes gh-12102
3 years ago
David Becker
2b426872a3
Use InetSocketAddress#getHostString
...
Sometimes InetSocketAddress#getAddress#getHostAddress retuns null.
In that case, call InetSocketAddress#getHostString instead.
There is no performance loss since IpAddressMatcher#matches attemptsi
to re-parse and resolve the address anyway.
Closes gh-11888
3 years ago
Marcus Da Coregio
ead587c597
Consistently handle RequestRejectedException if it is wrapped
...
Closes gh-11645
3 years ago
Marcus Da Coregio
6a2ca52aae
Consistently handle RequestRejectedException if it is wrapped
...
Closes gh-11645
3 years ago
Rob Winch
269c711a64
RequestAttributeSecurityContextRepository never null SecurityContext
...
Previously loadContext(HttpServletRequest) could return a Supplier that
returned a null SecurityContext
This commit ensures that null is never returned by the Supplier by
returning SecurityContextHolder.createEmptyContext() instead.
Closes gh-11606
3 years ago
Rob Winch
29db051f7a
Cache SecurityContextRepository.loadContext(HttpServletRequest) Result
...
Closes gh-11390
4 years ago
Zhivko Delchev
e97c5a533b
Reverse content type check
...
When MultipartFormData is enabled currently the CsrfWebFilter compares
the content-type header against MULTIPART_FORM_DATA MediaType which
leads to NullPointerExecption when there is no content-type header.
This commit reverse the check to compare the MULTIPART_FORM_DATA
MediaType against the content-type which contains null check and avoids
the exception.
closes gh-11204
Closes gh-11205
4 years ago
Zhivko Delchev
d882bfcf2b
Reverse content type check
...
When MultipartFormData is enabled currently the CsrfWebFilter compares
the content-type header against MULTIPART_FORM_DATA MediaType which
leads to NullPointerExecption when there is no content-type header.
This commit reverse the check to compare the MULTIPART_FORM_DATA
MediaType against the content-type which contains null check and avoids
the exception.
closes gh-11204
Closes gh-11205
4 years ago
Rob Winch
cfc057b629
StrictHttpFirewall allows CJKV characters
...
Closes gh-11264
4 years ago
Rob Winch
d94639a1bb
StrictHttpFirewall allows CJKV characters
...
Closes gh-11264
4 years ago
Rob Winch
29b2b7a977
StrictHttpFirewall allows CJKV characters
...
Closes gh-11264
4 years ago
Rob Winch
66d1cd592a
StrictHttpFirewall allows CJKV characters
...
Closes gh-11264
4 years ago
Rob Winch
077c9e0b3e
StrictHttpFirewall allows CJKV characters
...
Closes gh-11264
4 years ago
Rob Winch
e2eed33eca
Add StrictHttpFirewall.allow* new lines and separators
...
Issue gh-11264
4 years ago
Rob Winch
5bf478e72e
Fix Formatting
...
Issue gh-11264
4 years ago
Rob Winch
e0a6a9efa9
StrictHttpFirewall allows CJKV characters
...
Issue gh-11264
4 years ago
Marcus Da Coregio
b8b0661d73
Lock Dependencies for Release
4 years ago
Rob Winch
0dcb592b03
AntRegexRequestMatcher Optimization
...
Closes gh-11234
4 years ago
Rob Winch
0ece0e6012
Extract rejectNonPrintableAsciiCharactersInFieldName
...
Closes gh-11234
4 years ago
Rob Winch
7f121e82f4
AntRegexRequestMatcher Optimization
...
Closes gh-11234
4 years ago
Rob Winch
9059fb3fc7
Extract rejectNonPrintableAsciiCharactersInFieldName
...
Closes gh-11234
4 years ago
Rob Winch
1a9ec8a756
AntRegexRequestMatcher Optimization
...
Closes gh-11234
4 years ago
Rob Winch
4967a0394f
Extract rejectNonPrintableAsciiCharactersInFieldName
...
Closes gh-11234
4 years ago
Rob Winch
c6461d61ba
AntRegexRequestMatcher Optimization
...
Closes gh-11234
4 years ago
Rob Winch
4405cf18f3
Extract rejectNonPrintableAsciiCharactersInFieldName
...
Closes gh-11234
4 years ago
Rob Winch
70863952ae
AntRegexRequestMatcher Optimization
...
Closes gh-11234
4 years ago
Rob Winch
af95be34c6
Extract rejectNonPrintableAsciiCharactersInFieldName
...
Closes gh-11234
4 years ago
Rob Winch
ee28896f42
AntRegexRequestMatcher Optimization
...
Closes gh-11234
4 years ago
Rob Winch
6b823fb27e
Extract rejectNonPrintableAsciiCharactersInFieldName
...
Closes gh-11234
4 years ago
Rob Winch
67830f4111
Fix WebSessionReactiveSecurityRepository Supports Cache
...
Fix the checkstyle for this feature
Closes gh-8422
4 years ago
Rob Winch
c6eaa05fc5
WebSessionReactiveSecurityRepository Supports Cache
4 years ago
Rob Winch
aaf78330b1
ForceEagerSessionCreationFilter
...
Closes gh-11109
4 years ago
Marcus Da Coregio
7fea639a43
Add Option to Filter All Dispatcher Types
...
Closes gh-11092
4 years ago
Rob Winch
3a9b080bbe
Deprecate loadContext(RequestResponseHolder)
...
Fix gh-11032
4 years ago
Rob Winch
39b0620a84
Add DisableUrlRewritingFilter
...
Closes gh-11084
4 years ago
Eleftheria Stein
725a57fccc
Remove blocking call from ExceptionTranslationWebFilter
...
This also means that the exception message is no longer retrieved from a MessageSource. This is consistent with the other WebFilters.
Closes gh-10864
4 years ago
Josh Cummings
c175118f62
Use RequestMatcherEntry
...
Closes gh-11046
4 years ago
Josh Cummings
061f69eb70
Polish Authorization Event Support
...
- Added spring-security-config support
- Renamed classes
- Changed contracts to include the authenticated user and secured
object
- Added method security support
Issue gh-9288
4 years ago
Parikshit Dutta
bd9434882f
Add authorization events
...
Closes gh-9288
4 years ago