Josh Cummings
360db53dd2
Polish SAML Attribute Support
...
Issue gh-8661
6 years ago
Nikola Kostic
eed33228f4
Add SAML Attribute Support
...
Closes gh-8661
6 years ago
Craig Andrews
efb6953017
Reject the NULL character in paths in StrictHttpFirewall
...
Adds `setAllowNull`
By default, denies null in paths
6 years ago
Rob Winch
406cde8798
Use Spring Snapshots Again
...
Closes gh-8712
6 years ago
Ellie Bahadori
ca63af4a28
Remove Travis pipeline and README badge
6 years ago
Ellie Bahadori
7319e81701
Change pipeline to run for all base branches
...
Issue gh-8680
6 years ago
Josh Cummings
9895d01257
Simplify Multitenancy Example
...
Closes gh-8713
6 years ago
Rob Winch
145bb89394
Use Spring Releases for Now
...
Works around https://github.com/spring-projects/spring-framework/issues/25271
6 years ago
yukihane
c177b391d4
Polish ProviderManagerTests
...
- Renamed test to follow naming convention
- Simplified mock with Mockito
- Added note regarding related ticket
Issue gh-8689
6 years ago
yukihane
5302fb776c
ProviderManager Uses CollectionUtils#contains
...
Closes gh-8689
6 years ago
Ellie Bahadori
27e1c582b9
Merge pull request #8680 from elliedori/github-actions-pr-pipeline
...
Set up Github Actions pipeline for PRs
6 years ago
Eleftheria Stein
224361cb4a
Fix typo in Javadoc
6 years ago
Rob Winch
eb351f455b
Use `Closes gh-<number>`
...
We now use Closes because it makes sense for enhancements and bugs
6 years ago
Ellie Bahadori
e213e6430a
Create Github Actions pipeline for PR build workflow
6 years ago
Evgeniy Cheban
4e7be2078f
DefaultWebSecurityExpressionHandler uses RoleHierarchy bean
...
Fixes gh-7059
6 years ago
Rob Winch
ccbad61ae8
Change blacklist to blocklist
...
Closes gh-8676
6 years ago
Rob Winch
ca1252be94
Replace whitelist with allowlist
...
Issue gh-8676
6 years ago
Rob Winch
a907026eae
Deprecate X-FRAME-OPTIONS ALLOW-FROM Directive
...
Closes gh-8677
6 years ago
Rob Winch
6fbe58e624
Update RSocket Sample to use RSocket 1.0.1
...
Fixes the integration tests from hanging.
Issue gh-8664
6 years ago
Joe Grandja
da4b626bf1
OAuth2LoginAuthenticationWebFilter should handle OAuth2AuthorizationException
...
Issue gh-8609
6 years ago
Joe Grandja
4c902bb857
OAuth2AuthorizationCodeGrantWebFilter should handle OAuth2AuthorizationException
...
Fixes gh-8609
6 years ago
Robin Dupret
bb0fac66d6
Fix a few typos in the documentation
6 years ago
Josh Cummings
1d821a2664
Add Ticket Number to Test
...
Issue gh-8650
6 years ago
Erik Bakker
cd3fd6762f
Don't Consume Request Body
...
Per the servlet spec, getParameter(name) consumes the request body for
POST requests.
This commit prevents DefaultOAuth2AuthorizationRequestResolver from
consuming the request body for non-Authorization requests.
Closes gh-8650
6 years ago
Rob Winch
24a04f9c5f
Add subscriberContext to PayloadSocketAcceptor delegate.accept
...
Closes gh-8654
6 years ago
Parikshit Dutta
28d2cfa14a
Add ServerRequestCache setter in OAuth2AuthorizationCodeGrantWebFilter
...
Fixes gh-8536
6 years ago
Josh Cummings
aa84c79e87
Use Nimbus Multiple Algorithm Support
...
Closes gh-8623
6 years ago
Dayan
d8aa208a9f
Fix broken link in spring security reference document
...
Fixes:#8593
6 years ago
Rob Winch
748538d19f
Delay AuthenticationPrincipalArgumentResolver Creation
...
Use ObjectProvider<AuthenticationPrincipalArgumentResolver> to delay its
lookup.
Closes gh-8613
6 years ago
Eleftheria Stein
a63a0e3765
Add reactive CSRF samples to docs
...
Issue gh-8172
6 years ago
Josh Cummings
da05543ef6
Update OAuth 2.0 Client Testing Docs
...
Issue gh-8603
6 years ago
Josh Cummings
42a8635cde
Remove @MockBean ClientRegistrationRepository
...
Fixes gh-8606
6 years ago
Josh Cummings
d5b8981678
Polish OAuth 2.0 Samples
...
- Favor @TestConfiguration so as to not disable Spring Boot's
auto-configuration of ClientRegistrationRepository and
OAuth2AuthorizedClientRepository
6 years ago
Josh Cummings
8d84bc58f6
Remove Unneeded OAuth2AuthorizedClientRepository
...
Issue gh-8603
6 years ago
Josh Cummings
900f551890
Inject TestOAuth2AuthorizedClientRepository
...
Fixes gh-8603
6 years ago
Josh Cummings
d014d29199
Update to Spring Boot 2.3.0
...
Fixes gh-8605
6 years ago
Josh Cummings
b6f5464fb4
Update to Latest rsocket-core
...
Now that the RSocket Authentication Extension is GA, it's no longer
necessary to override the version locally in the sample.
Issue gh-7935
6 years ago
Josh Cummings
23db372962
Update to Gradle 6.4.1
...
Fixes gh-8604
6 years ago
Eleftheria Stein
61060b3a4f
Add multipart configuration to CSRF Kotlin DSL
...
Fixes gh-8602
6 years ago
Eleftheria Stein
6f5947cab7
Fix test warnings
6 years ago
Eleftheria Stein
fa11ae3c33
Remove unused import
6 years ago
Markus Engelbrecht
7463583c1b
Fix typos in BCryptPasswordEncoder documentation
...
Resolves gh-8585
6 years ago
Spencer Gilson
551f9114a9
Fixing typo in README
...
@pivotal-issuemaster This is an Obvious Fix
6 years ago
Eleftheria Stein
67d2efde1c
Resolve package tangles with security marker annotation
6 years ago
Eleftheria Stein
bc272ddf73
Resolve package tangles in Kotlin server package
6 years ago
Eleftheria Stein
0a42aa26c8
Mock request with non-standard HTTP method in test
...
Fixes gh-8594
6 years ago
Craig Andrews
f1db7167cb
Polish
...
Use `getBeanOrNull` in `registerDelegateApplicationListener` to simplify implementation.
This change does not alter behavior.
6 years ago
Craig Andrews
dbdeec4216
Check for an existing SessionRegistry bean
...
If a SessionRegistry is necessary, check for one in the ApplicationContext before creating one.
6 years ago
Evgeniy Cheban
0fa339f75b
Allow port=0 for ApacheDSContainer
...
Fixes gh-8144
6 years ago
justmehyp
06254a4fd4
Remove unused field 'digester' in Md4PasswordEncoder
...
`private Digester digester;` defined in Md4PasswordEncoder is never used. So remove it.
6 years ago