4289 Commits (077af5e187cd916814335e46f9309c25c70d3925)
 

Author SHA1 Message Date
Luke Taylor 077af5e187 SEC-1661: Use a DistinguishedName to wrap the search base to avoid the need for JNDI escaping. 15 years ago
Luke Taylor 866615ceaa SEC-1662: Cater for the case where a user uses two <http> elements without patterns and the RequestMatcher does not have two arguments. 15 years ago
Luke Taylor d58dd79a52 SEC-1494: Updated the tutorial webapp to use CSS and make use of the securityHiddenUI element when UI security is disabled. 15 years ago
Luke Taylor 00200cecbc SEC-1494: Added system property "spring.security.disableUISecurity" which will prevent authorize tags from hiding content. By default, the property will also cause the area that would normally be hidden to be decorated with a <span class="securityHiddenUI"> tag, thus allowing the area to be rendered with some distinguishing css (e.g. a different background colour). 15 years ago
Rob Winch 1b32babbf9 SEC-1545: Removed unused i18n keys, changed keys to follow naming conventions, found missing keys based upon old keys, sorted keys, any unknown keys are entered as a comment with the English value. 15 years ago
Luke Taylor 95b416b0e7 SEC-1660: Minor addition to FAQ text. 15 years ago
Luke Taylor b542c73907 SEC-1660: Updated FAQ to explain that session-fixation protection may cause problems if switching between HTTP and HTTPS, and also updated information to advise against switching in the first place. 15 years ago
Luke Taylor 6b1b012e2c Added check for maximum AES key size in crypto.gradle to skip tests if limited strength crypto policy files are in place. 15 years ago
Luke Taylor 594f6694bb Add logging of jdk version to crypto build file 15 years ago
Luke Taylor d686f64f26 Skip EncryptorsTests when using <JDK 1.6 as AES isn't available 15 years ago
Luke Taylor 60befb063a SEC-1659: Added crypto module to list of project modules in reference manual intro and to dependencies appendix. 15 years ago
Luke Taylor 162cb64baa SEC-1659: Label crypto utils package as only for internal use. 15 years ago
Keith Donald 38327d1b16 SEC-1659: crypto docs 15 years ago
Keith Donald b646e44646 SEC-1659: fixed bundlor step of build 15 years ago
Keith Donald ea76efdb2c SEC-1659: favor AES encryption instead of DES as standard symmetric encryption algorithm 15 years ago
Keith Donald ffa7301e7f SEC-1569: initial commit of spring-security-crypto module, consisting of encrypt, keygen, password, and util packages 15 years ago
Luke Taylor afd586c96e Re-instate the CAS integration sequence description in the CAS chapter, with corrections (and minus proxying). 15 years ago
Luke Taylor 2eefbf3a23 SEC-1657: Added support for 'name' attribute in <http> element to expose filter chain as a list bean. 15 years ago
Rob Winch f20649f035 SEC-1648: added null check for getTargetUrlParameter() in SavedRequestAwareAuthenticationSuccessHandler.onAuthenticationSuccess and updated validation for AbstractAuthenticationTargetUrlRequestHandler.setTargetUrlParameter 15 years ago
Luke Taylor 075b30ab44 SEC-1651: Added paragraph to FAQ mentioning dependencies appendix. 15 years ago
Luke Taylor 8da0de459b SEC-1651: Added remaining module information to dependencies appendix. 15 years ago
Luke Taylor 79b8edbd1e Update CAS client to 3.1.12 15 years ago
Luke Taylor eeb466b613 SEC-1648: Implemented Rob's suggestion to use a null value for the targetUrlParameter rather than a boolean property. It should thus only be used if this value is set. 15 years ago
Luke Taylor 6de2197c0f SEC-1653: Ensure UserDetailsServiceFactoryBean is registered using the tools API to prevent errors in STS. 15 years ago
Luke Taylor 19e56f4397 Stripping out unnecessary dependencies from sample jars. 15 years ago
Luke Taylor 39b48c6d95 Update gradle wrapper to 0.9.1 in order to use mavenLocal() repo syntax. 15 years ago
Luke Taylor bf59c75886 Test class to improve coverage of WAS-specific preauth code. 15 years ago
Luke Taylor b858b23927 SEC-1651: Added first draft of dependencies appendix to reference manual. 15 years ago
Luke Taylor 6779822325 Remove GRADLE-1090 workarounds from config.gradle. 15 years ago
Luke Taylor 8d7830a1ee SEC-1603: Add support in namespace for use of AuthenticationSuccessHandler with remember-me. 15 years ago
Luke Taylor 7fd3aa2b45 SEC-1603: Add support for injecting an AuthenticationSuccessHandler into RememberMeAuthenticationFilter. 15 years ago
Luke Taylor c1f2fa1983 SEC-1558: Changed signatures of PrePostInvocationAttributeFactory to take strings rather than annotation types to allow the metadata to be obtained from other sources (not just annotations). 15 years ago
Luke Taylor 423f9eae7a SEC-1648: Added a useTargetUrlparameter property to AbstractAuthenticationTargetUrlRequestHandler which defaults to false. 15 years ago
Luke Taylor 313fe78cc1 Corrected snapshot version 15 years ago
Luke Taylor 2487a3e27b Reset to snapshot version 15 years ago
Luke Taylor 0ca5157f47 Set project release version to 3.1.0.M2 15 years ago
Luke Taylor 7316bcff75 Updated outdated CAS sample readme with instructions for running CAS using gradle 15 years ago
Luke Taylor bbcc611af5 CAS server version upgrade and minor tweaks to CAS sample build file. 15 years ago
Luke Taylor 592782dc7f Added test for getAdditionalRoles in DefaultLdapAuthoritiesPopulator. 15 years ago
Luke Taylor eebcfd28ef Move Ldap authorities populator tests to the correct package. 15 years ago
Luke Taylor dbe270f132 SEC-1641: Correct code and test for null groupSearchBase. 15 years ago
Luke Taylor 428a0b7dce SEC-1639: Removed url argument from FilterChainProxy's VirtualFilterChain, since this can be directly computed from the request instance in the debug statements. 15 years ago
Luke Taylor 5f6dab67e1 SEC-1492: Added SimpleAuthoritiesMapper which provides a one-to-one authority mapping with case-conversion and the addition of a "role" prefix to the authority name. 15 years ago
Luke Taylor 3547cfcc92 SEC-1641: Remove the private setGroupSearchBase method and allowed a null value to be set for the group search base in the constructor. 15 years ago
Luke Taylor f1fe3ce7e6 Update wrapper to gradle 0.9 release 15 years ago
Luke Taylor 48ea0a6249 SEC-1638: Added paragraph to docs explaining that for complete security, an app should not switch out of HTTPS at all. 15 years ago
Luke Taylor 7cf9740fd4 SEC-1638: Added an example configuration to the Javadoc for ChannelProcessingFilter and a pointer from the reference manual. 15 years ago
Rob Winch 1ed5227d75 Removed @Override from HttpFirewallBeanDefinitionParser.parse since it does not override a method definition, it implements one. 15 years ago
Rob Winch 7c04fdbc90 SEC-1639: FirewalledRequest is now called on the specific FirewalledRequest instance rather that looping through ServletRequestWrappers. 15 years ago
Luke Taylor 46f83c8a08 SEC-1492: Added RoleHierarchyAuthoritiesMapper as the new preferred way of using a RoleHierarchy. 15 years ago