Eleftheria Stein
256aba7b37
Fix rsocket test
...
Request route that exists; add additional error message verification
Fixes gh-8154
6 years ago
Erik van Paassen
86e25ff2ab
Fix typo in Javadoc of HttpSecurity#csrf()
...
`HttpSecurity#csrf()` obviously returns a `CsrfConfigurer`, while the Javadoc states that it returns the `ServletApiConfigurer`.
6 years ago
Zeeshan Adnan
a49a325db2
Fix exception for empty basic auth header token
...
fixes spring-projectsgh-7976
6 years ago
Markus Engelbrecht
75f22285c6
Fix typo 'properites' in documentation
...
Fixes gh-8095
6 years ago
Josh Cummings
8fa16ce63e
Update to Jetty 9.4.27
...
Fixes gh-7507
6 years ago
Clement Stoquart
32c02fbedb
Remove empty relay state from redirect url
6 years ago
AmitB
96ff3a54a9
Fix typo in AntPathRequestMatcher contructor comment
6 years ago
Josh Cummings
9092115b8a
Register Authentication Provider in Init Phase
...
Fixes gh-8031
6 years ago
Joe Grandja
3dbfef9ef1
OAuth2AccessTokenResponseHttpMessageConverter handles JSON object parameters
...
Fixes gh-6463
6 years ago
Joe Grandja
8acdb82e6a
OAuth2AuthorizationCodeGrantWebFilter matches on query parameters
...
Fixes gh-7966
6 years ago
Rafael Renan Pacheco
5ce0ce3f38
Fix var typo and code readability
6 years ago
Joe Grandja
6141132cfa
Fix test gh-7963
6 years ago
Joe Grandja
cc7ea4acd3
OAuth2AuthorizationCodeGrantFilter matches on query parameters
...
Fixes gh-7963
6 years ago
Manuel Bleichenbacher
1e4736f9b3
Prevent double-escaping of authorize URL parameters
...
If the authorization URL in the OAuth2 provider configuration contained query parameters with escaped characters, these characters were escaped a second time. This commit fixes it.
It is relevant to support the OIDC claims parameter (see https://openid.net/specs/openid-connect-core-1_0.html#ClaimsParameter ).
Fixes gh-7871
6 years ago
Stephane Maldini
0012e24c46
Don't force downcasting of RequestAttributes to ServletRequestAttributes
...
Fixes gh-7953
6 years ago
Joe Grandja
2dc8147106
Add release-notes-sections.yml
6 years ago
Joe Grandja
1da8e9df13
Next Development Version
6 years ago
Joe Grandja
9a2b71d931
Release 5.2.2.RELEASE
6 years ago
Josh Cummings
c4ccc96655
Polish Error Messages for OpaqueTokenIntrospectors
6 years ago
Joe Grandja
6c310213a8
Update to Spring Boot 2.2.4
...
Fixes gh-7909
6 years ago
Joe Grandja
a5b6b9a398
Update to org.slf4j 1.7.30
...
Fixes gh-7908
6 years ago
Joe Grandja
9e6910273c
Update to org.powermock 2.0.5
...
Fixes gh-7907
6 years ago
Joe Grandja
ea809b01a6
Update to hibernate-validator 6.1.2.Final
...
Fixes gh-7906
6 years ago
Joe Grandja
8054239a12
Update to hibernate-entitymanager 5.4.10.Final
...
Fixes gh-7905
6 years ago
Joe Grandja
46486194c2
Update to org.aspectj 1.9.5
...
Fixes gh-7904
6 years ago
Joe Grandja
00b08bc725
Update to httpclient 4.5.11
...
Fixes gh-7903
6 years ago
Joe Grandja
6e0fbfcccd
Update to commons-codec 1.14
...
Fixes gh-7899
6 years ago
Joe Grandja
87ea083520
Update to com.squareup.okhttp3 3.14.6
...
Fixes gh-7898
6 years ago
Joe Grandja
9db3f51f2a
Update to Jackson 2.10.2
...
Fixes gh-7897
6 years ago
Joe Grandja
3cc4a945c6
Update to Reactor Dysprosium SR4
...
Fixes gh-7896
6 years ago
Joe Grandja
dbc43fb47d
Update to Spring Data Moore SR3
...
Fixes gh-7895
6 years ago
Joe Grandja
ce6a0368bd
Update to Spring Framework 5.2.3
...
Fixes gh-7894
6 years ago
Eleftheria Stein
9dd3dfe718
Fix requiresAuthenticationMatcher not being used
...
The custom server requiresAuthenticationMatcher was not always picked up
Fixes: gh-7863
6 years ago
Eleftheria Stein
edb6cd3729
Fix authenticationFailureHandler not being used
...
The custom server authenticationFailureHandler was not always picked up
Fixes: gh-7782
6 years ago
Peter Keller
2dbedf7af5
Set charset of BasicAuthenticationFilter converter
...
Allow BasicAuthenticationFilter to pick up the given credentials charset.
Fixes: gh-7835
6 years ago
Eleftheria Stein
630eb10704
Load LDIF file from classpath in unboundId mode
...
Fixes: gh-7833
6 years ago
Eleftheria Stein
f4d4c08329
Fix LDIF file example in LDAP docs
...
Fixes: gh-7832
6 years ago
Johannes Edmeier
cc956a66df
Don't cache requests with `Accept: text/event-stream` by default.
...
The eventstream requests is typically not directly invoked by the browser.
And even more unfortunately the Browser-Api doesn't allow the set additional headers as `XMLHttpRequest`..
6 years ago
Rob Winch
29182abb34
Fix HttpHeaderWriterWebFilterTests
...
Ensure setComplete() is subscribed to
6 years ago
Filip Hanik
b754a3d635
Use the custom ServerRequestCache that the user configures
...
on for the default authentication entry point and authentication
success handler
Fixes gh-7721
https://github.com/spring-projects/spring-security/issues/7721
Set RequestCache on the Oauth2LoginSpec default authentication success handler
import static ReflectionTestUtils.getField
Feedback incorporated per
https://github.com/spring-projects/spring-security/pull/7734#pullrequestreview-332150359
6 years ago
Eleftheria Stein
0d24e2b8cf
Fix WebFlux logout disabling
...
Fixes: gh-7682
6 years ago
Rob Winch
b00999deed
Docs ServerRSocketFactoryCustomizer->ServerRSocketFactoryProcessor
...
The documentation incorrectly used ServerRSocketFactoryCustomizer which
was renamed to ServerRSocketFactoryProcessor. The docs now use the correct
class name
Fixes gh-7737
6 years ago
Eleftheria Stein
59ca2ddf65
Polish SAML2 principal classes
...
Update @since
Issue: gh-7681
6 years ago
Clement Stoquart
0782228914
fix: make Saml2Authentication serializable
6 years ago
Rob Winch
29eb8b9177
CompositeServerHttpHeadersWriter Executes Sequentially
...
Fixes gh-7731
6 years ago
Rob Winch
bd6ff1f319
DelegatingServerAuthenticationSuccessHandler Executes Sequentially
...
Fixes gh-7728
6 years ago
Rob Winch
6db7b457b7
DelegatingServerLogoutHandler Executes Sequentially
...
Fixes gh-7723
6 years ago
Phil Clay
840d3aa986
Polish #7589
...
Rename OAuth2AuthorizedClientServiceReactiveOAuth2AuthorizedClientManager to AuthorizedClientServiceReactiveOAuth2AuthorizedClientManager.
Handle empty mono returned from contextAttributesMapper.
Handle empty map returned from contextAttributesMapper.
Fix DefaultContextAttributesMapper so that it doesn't access ServerWebExchange.
Fix unit tests so that they pass.
Use StepVerifier in unit tests, rather than .subscribe().
Fixes gh-7569
6 years ago
Ankur Pathak
4c5c4f6cce
Reactive Implementation of AuthorizedClientServiceOAuth2AuthorizedClientManager
...
ReactiveOAuth2AuthorizedClientServiceReactiveOAuth2AuthorizedClientManager is reactive
version of AuthorizedClientServiceOAuth2AuthorizedClientManager
Fixes: gh-7569
6 years ago
Joe Grandja
148b570a98
Remove redundant validation for redirect-uri
...
Fixes gh-7706
6 years ago