Kazuki Shimizu
205ef42cfb
SEC-3147: Add error parameter for default authentication-failure-url
10 years ago
Rob Winch
53f85e2151
SEC-2848: LogoutConfigurer allows setting clearAuthentication
10 years ago
Rob Winch
15b4406015
SEC-3135: antMatchers(<method>,new String[0]) now passive
10 years ago
Rob Winch
6f1bb705ac
SEC-3135: antMatchers now allows method and no pattern
...
Previously, antMatchers(POST).authenticated() was not allowed. Instead
users had to use antMatchers(POST, "/**").authenticated().
Now we default the patterns to be "/**" if it is null or empty.
10 years ago
Rob Winch
f76bf96e14
SEC-3132: securityBuilder cannot be null
...
If a custom SecurityConfiguererAdapter applies another
SecurityConfigurerAdapter it caused an error securityBuilder cannot be null.
This commit fixes this.
10 years ago
Rob Winch
b9f8af3096
SEC-3063: rm ConditionalOnMissingBean for @Primary
...
ConditionalOnMissingBean can only work in a Spring Boot environment. This
means this approach is flawed.
Instead users that wish to override requestDataValueProcessor can use
@Primary .
10 years ago
izeye
8baafbb2f2
SEC-3116: Polish WebSecurity Javadoc
10 years ago
zhanhb
29f2cc0ab1
snasphot -> snapshot
10 years ago
Rob Winch
bac980cbcb
SEC-2868: Simplify custom UserDetailsService Java Config
...
Exposing a UserDetailsService as a bean is now all that is necessary
for Java based configuration. Additionally, an optional PasswordEncoder
bean can be used to configure password encoding.
11 years ago
Rob Winch
6b05b298ff
SEC-2059: Support Path Variables in Web Expressions
11 years ago
Rob Winch
cbed1d75ee
SEC-3076: Add Method Level Security Meta Annotations
11 years ago
Rob Winch
41c9431fcc
Test that form log in requires CSRF
11 years ago
Rob Winch
453e6332da
Fix indentation of CsrfConfigTests
11 years ago
Rob Winch
969f3a7d1b
Update pom.xml to latest snapshots
11 years ago
Thomas Darimont
ad1d858e2b
SEC-3056 - Fix JavaDoc errors.
...
Fixed JavaDoc errors accross multiple modules in order to make javadoc happy with Java 8.
11 years ago
Rob Winch
dab4cf18b8
SEC-3032: Correct documented logout-success-url default
11 years ago
Rob Winch
e8c9f75f9c
Update pom.xml to latest versions
11 years ago
Rob Winch
07fb2af74b
SEC-3011: AbstractUrlAuthorizationConfigurer postProcess default AccessDecisionManager
11 years ago
Rob Winch
ab1b7a1eb6
Remove unnecessary @SuppressWarnings
11 years ago
Rob Winch
9654df2cc3
SEC-3045: Conditionally add MethodSecurityMetadataSourceAdvisor
11 years ago
Rob Winch
a3df41b380
Clean Import Statements
11 years ago
Rob Winch
0e36f85dab
SEC-3019: Java Config for Http Basic supports Rememberme
11 years ago
Rob Winch
474d624e8e
SEC-2988: Renamed OnBeanCondition.java to OnMissingBeanCondition.java
11 years ago
Rob Winch
64938ebcfc
SEC-2996: Suport configuring SecurityExpressionHandler<Message<Object>>
11 years ago
Stijn
ca0ffb8b5d
SEC-2948: Fix error message for wrong xsd schema
...
When using the wrong xsd schema < 4.0 a message was shown that the
schema needed to be version 3.2.
In reality this schema had to be version 4.0.
11 years ago
Rob Winch
1f74ac811e
Fix Spring IO Tests
11 years ago
Rob Winch
197ddb3cd1
SEC-3029: Fix Compatibility with Spring 4.2.x
11 years ago
Alex Panchenko
0a118336d4
SEC-2955: Convert to "static" for inner classes
11 years ago
Rob Winch
f1352ba492
SEC-2942: Add test EnableWebSecurity supports AuthenticationPrincipal
11 years ago
Rob Winch
f548d89b27
SEC-2932: SecurityContextConfigurer defaults SecurityContextRepository
11 years ago
Rob Winch
09acc2b7a5
SEC-2962: SecurityContextHolderAwareRequestFilter default rolePrefix
11 years ago
Rob Winch
38e2e23b86
Fix indentation of InterceptUrlConfigTests
11 years ago
Rob Winch
d5dfeeca49
SEC-2927: Update chat-jc pom so Maven Builds
...
Previously there were some incorrect dependency versions. This commit fixes
that.
We added dependencyManagement for Spring Framework and corrected
Thymeleaf and embedded redis versions.
11 years ago
Rob Winch
0bfbd2923a
SEC-2915: Fix defaut login page tests with tabs
11 years ago
Rob Winch
4fdfb8caba
SEC-2915: More Tabs -> Spaces
11 years ago
Rob Winch
5fa5630bc3
Polish ordering of Config and test in NamespaceRememberMeTests
...
The convention is to put the config just below the test.
This commit fixes the convention for NamespaceRememberMeTests
11 years ago
Kazuki Shimizu
0c77c2071b
SEC-2880: Add a setter method to override the cookie name of remember-me
11 years ago
Rob Winch
ec89fdcfaa
SEC-2919: Polish
...
Remove now unnecessary AuthenticationConfig.Builder#getLoginFormUrl
method.
11 years ago
Rob Winch
052bd32f40
SEC-2919: DefaultLoginPageGeneratingFilter disabled when login-page specified
11 years ago
Rob Winch
4ca936bb76
SEC-2913: Polish
11 years ago
Rob Winch
6c541468f6
SEC-2913: Post Process default session fixation AuthenticationStrategy
...
Before the default session fixation AuthenticationStrategy used a
NullEventPublisher when using the Java Configuration. This was due to the
fact that it is not exposed as a Bean and is not post processed.
We now post process the default session fixation AuthenticationStrategy
which initializes the EventPublisher properly.
11 years ago
Rob Winch
7b25b3e40d
SEC-2864: Default Spring Security WebSocket PathMatcher XML Namespace
11 years ago
Rob Winch
db531d9100
SEC-2917: Update to Spring 4.1.6
11 years ago
Rob Winch
57b06fb0b5
SEC-2864: Default Spring Security WebSocket PathMatcher
11 years ago
Rob Winch
c94a5cf8e2
SEC-2916: disable-url-rewriting=true by default
11 years ago
Rob Winch
ae6af5d73c
SEC-2915: Updated Java Code Formatting
11 years ago
Rob Winch
0a2e496a84
SEC-2915: groovy/gradle spaces->tabs
11 years ago
Rob Winch
cf9f58a4ac
SEC-2915: XML spaces->tabs
11 years ago
Rob Winch
fbf3672eca
SEC-2908: mulitple invocations of http.requetMatchers() properly chains
11 years ago
Rob Winch
e776a1fd35
SEC-2803: Add HttpStatusEntryPoint
11 years ago