99 Commits (05d55ea83ab9e4108879fda170b32a634538635b)

Author SHA1 Message Date
Ben Alex a5000972fb Add RC1. 20 years ago
Ben Alex 079e22e5d8 Refer to 1.0.0 release work in progress. 20 years ago
Ben Alex edf3b466c4 Fix so multiproject:site doesn't fail. 20 years ago
Ben Alex 54aaefa703 Move changelog for 0.9.0 to JIRA after adding the tasks previously in changes.xml. 20 years ago
Mark St. Godard 9b898e84c4 Added Java 5 Annotations version of Contacts sample (contacts-tiger). 21 years ago
Ben Alex f5741962ed Add createSessionAllowed property, which should be set to false to avoid unnecessary session creation. 21 years ago
Ben Alex 35ca25f085 BasicAuthenticationProcessingFilter no longer creates HttpSession via WebAuthenticationDetails call. 21 years ago
Ben Alex 55f5c3397a Relocated JdbcDaoExtendedImpl.convertAclObjectIdentityToString to superclass (pursuant to suggestion made by Tim Kettering on acegisecurity-developer). 21 years ago
Ben Alex e805aa2e73 Add annotation support. 21 years ago
Mark St. Godard ec5e39c2e8 Initial checkin of user security context switching (see SEC-15). This is the first cut of the SwitchUserProcessingFilter that handles switching to a target uesr and exiting back to the original user. Note: This is going to be used for the common use-case of an Administrator 'switching' to another user (i.e. ROLE_ADMIN -> ROLE_USER). This is the initial cut of a Unix 'su' for Acegi managed web applications. 21 years ago
Scott McCrory c2c48b905b Added package.html files to reamining java packages (see http://opensource.atlassian.com/projects/spring/browse/SEC-41) 21 years ago
Scott McCrory f4c8211cc2 Replaced .cvsignore placeholders for package.html files (which also serve some doccumentary purpose). 21 years ago
Scott McCrory db4ed4bc44 Added debug statement to AbstractTicketValidator to help with Acegi+CAS+SSL setup (thanks Seth Ladd for the patch) (see http://opensource.atlassian.com/projects/spring/browse/SEC-34) 21 years ago
Scott McCrory c66c5dfab5 AuthorizeTag no longer depends on JDK 1.4. Tested on Websphere 5.0 w/JDK 1.3 (see http://opensource.atlassian.com/projects/spring/browse/SEC-11) 21 years ago
Ben Alex f20bc6d9d0 Catch up with recent changes. 21 years ago
Ben Alex f650289142 Avoid expense of HttpSession when working with anonymous users. 21 years ago
Ben Alex c8275c591f Reflect additional releases made for backporting SEC-20 security fix. 21 years ago
Ben Alex 3e4a29eae9 FilterSecurityInterceptor now has an observeOncePerRequest boolean property, allowing multiple fragments of the HTTP request to be individually authorized (see http://opensource.atlassian.com/projects/spring/browse/SEC-14). 21 years ago
Ben Alex d09d250656 Form, CAS, X509 and Remember-Me authentication mechanisms now publish an InteractiveAuthenticationSuccessEvent (see http://opensource.atlassian.com/projects/spring/browse/SEC-5). 21 years ago
Ben Alex 60f8095cf2 Make Authenticated.isAuthenticated() behaviour switchable. See http://opensource.atlassian.com/projects/spring/browse/SEC-13. 21 years ago
Ben Alex ef8281f534 HttpSessionContextIntegrationFilter elegantly handles IOExceptions and ServletExceptions within filter chain (see http://opensource.atlassian.com/projects/spring/browse/SEC-20). 21 years ago
Ben Alex a3d26edea3 JBoss container adapter to use getName() instead to toString() (see http://opensource.atlassian.com/projects/spring/browse/SEC-22). 21 years ago
Ben Alex a312fede74 Refactor DAO authentication failure events under a consistent abstract superclass (thanks to Mark St Godard for suggestion). 21 years ago
Ben Alex c0f1d4e19d Remove getters and setters from JdbcDaoImpl so IoC container cannot modify MappingSqlQuerys (thanks to David Durham for bug report). 21 years ago
Ben Alex a15691d9d7 Silently catch NotSerializableException in AbstractProcessingFilter if rootCause is not Serializable (thanks to Joseph Dane for reporting this bug). 21 years ago
Ben Alex 5f75e9bf9a Refactor Authentication.isAuthenticated() handling to be more performance (as per developer list discussion). 21 years ago
Ben Alex a7b5299e77 Correct synchronization issue with FilterToBeanProxy initialization (thanks to George Franciscus and Volker Malzahn as per acegisecurity-developer discussion 4 June 2005). 21 years ago
Ben Alex c699f7d40e Support non-username as primary key. 21 years ago
Ben Alex 4e55780e7c Performance optimisations thanks to Paulo Neves. 21 years ago
Ben Alex cfb8271826 Reorder DaoAuthenticationProvider exception logic as per developer list discussion. 21 years ago
Ben Alex ecbfac2ff8 Made AclEntry Serializable (correct issue with BasicAclEntryCache). 21 years ago
Ben Alex e08e66dec6 Refactor SecurityContextHolder to return a SecurityContext instead of Authentication. 21 years ago
Ben Alex 6a9abe5d90 Remove ContextHolder and introduce SecurityContext. 21 years ago
Luke Taylor d4da559ccc added entry for credential expiry modifications 21 years ago
Ben Alex d169829f27 AbstractAuthenticationToken.getName() now returns username alone if UserDetails present. 21 years ago
Ray Krueger 6f286e2054 AuthorityGranter.grant now returns a java.util.Set of role names, instead of a single role name 21 years ago
Ben Alex cff9ba4988 AnonymousProcessingFilter offers protected method to control when it should execute as per http://forum.springframework.org/viewtopic.php?p=19766. 21 years ago
Ben Alex a68d720e88 Prepare for 0.9.0. 21 years ago
Ben Alex 4cf500763f Release 0.8.2. 21 years ago
Ben Alex efd8955a3d General update. 21 years ago
Ben Alex fdf5c63033 Add obtainUsername method as per http://forum.springframework.org/viewtopic.php?t=4757. 21 years ago
Ben Alex 2ee7cc1c18 General update. 21 years ago
Ben Alex 204da55a0b PasswordDaoAuthenticationProvider no longer stores String against Authentication.setDetails(). 21 years ago
Ray Krueger 9649003d57 AbstractProcessingFilter no longer uses a set*FailureUrl approach for every exception, it now uses a properties object that maps authenticationExceptions to failure urls 21 years ago
Ben Alex 684d5bc10e Handle null Authentication.getAuthorities() in AuthorizeTag. 21 years ago
Ben Alex 8e6305ae81 Update commons-codec dependency to 1.3. 21 years ago
Ben Alex 8ae2276843 TokenBasedRememberMeServices changed to use long instead of int for tokenValiditySeconds. 21 years ago
Ben Alex 8884ca51af Add credentialsExpiredFailureUrl getter/setter to AbstractProcessingFilter. 21 years ago
Ben Alex 747825cda1 Correct location of AuthenticationSimpleHttpInvokerRequestExecutor in clientContext.xml. 21 years ago
Ben Alex 01aaadbe0d Prepare for 0.8.2 (assuming 0.8.2 is the next version, but subject to change). 21 years ago