Josh Cummings
39f4fcd5f2
Add AuthenticationEntryPointFailureHandler Preparation Steps
...
Issue gh-9429
3 years ago
Josh Cummings
ac7f726a24
Add RunAsManager Preparation Steps
...
Closes gh-11337
3 years ago
Josh Cummings
c5badbc631
Add AccessDecisionManager Preparation Steps
...
Issue gh-11337
3 years ago
Josh Cummings
86c9d5cfbe
Remove Stray Horizontal Rules
...
Issue gh-11337
3 years ago
Rob Winch
4112adf6a0
Document Configure Default CsrfTOken BREACH Protection
...
Closes gh-12107
3 years ago
Rob Winch
96d7c78b67
Polish Document Defer load CsrfToken
...
Issue gh-12105
3 years ago
Rob Winch
d860775b45
Document Defer load CsrfToken
...
Closes gh-12105
3 years ago
Josh Cummings
4938c394e4
Move Opt-out Steps
...
Closes gh-12104
3 years ago
Josh Cummings
8da916fa1c
Add Request Security Preparation Steps
...
Issue gh-11337
3 years ago
Josh Cummings
e900ca3a86
Polish Method Security Preparation Steps
...
- Add instruction to declare 5.8 defaults
Issue gh-11337
3 years ago
Josh Cummings
b4974bbce9
Polish Message Security Preparation Steps
...
- Added step to declare the 5.8 default in case later preparation steps
cannot be taken yet
Issue gh-11337
3 years ago
Josh Cummings
31a1486b88
Add Message Security Preparation Steps
...
Issue gh-11337
3 years ago
Rob Winch
5721b0351e
Polish RequestCache continue Kolin Configuration
...
Issue gh-12089
3 years ago
Rob Winch
aac1261f0c
Document Migration to SecurityContextHolderFilter
...
Closes gh-12098
3 years ago
Josh Cummings
1dd13e69a4
Standardize Preparation Guide Layout
...
Closes gh-12096
3 years ago
Josh Cummings
2a95a24390
Add Link to 6.0 Migration Guide
...
Issue gh-12093
3 years ago
Rob Winch
24cc7ff178
Document Saved Requests Migration
...
Closes gh-12089
3 years ago
Rob Winch
c17e258a6f
Document Saved Requests
...
Closes gh-12088
3 years ago
Josh Cummings
f6731e89db
Polish Method Security Preparation Steps
3 years ago
Josh Cummings
04fa5af794
Add Missing Doc Header
...
The EnableMethodSecurity section
3 years ago
Josh Cummings
e505bc3af4
Add Method Security Preparation Steps
3 years ago
Steve Riesenberg
5a55987d6e
Add links to reference in What's New for 5.8
...
Issue gh-4001
Issue gh-11959
3 years ago
Josh Cummings
59c4538798
Update What's New
...
Closes gh-12021
3 years ago
Joe Grandja
ffbcaca24a
Update reference for PasswordEncoders
...
Issue gh-10506
3 years ago
Marcus Da Coregio
4b6fed0667
Add static factory method to AntPathRequestMather and RegexRequestMatcher
...
Closes gh-11938
3 years ago
Steve Riesenberg
f462134e87
Add reactive support for BREACH
...
Closes gh-11959
3 years ago
Marcus Da Coregio
f3321c256c
Add XML support for shouldFilterAllDispatcherTypes
...
Closes gh-11492
3 years ago
Steve Riesenberg
dce1c30522
Add support for BREACH
...
Closes gh-4001
4 years ago
Steve Riesenberg
c1fcf275d9
Update What's New for 5.8
...
Issue gh-11952
4 years ago
Marcus Da Coregio
ace8caa182
Remove mvcMatchers usage from docs
...
Issue gh-11347
4 years ago
Steve Riesenberg
475b3bb6bb
Add deferred CsrfTokenRepository.loadDeferredToken
...
* Move DeferredCsrfToken to top-level and implement Supplier<CsrfToken>
* Move RepositoryDeferredCsrfToken to top-level and make package-private
* Add CsrfTokenRepository.loadToken(HttpServletRequest, HttpServletResponse)
* Update CsrfFilter
* Rename CsrfTokenRepositoryRequestHandler to CsrfTokenRequestAttributeHandler
Issue gh-11892
Closes gh-11918
4 years ago
Daniel Garnier-Moiroux
0e215a21ad
Add X-Xss-Protection headerValue to XML config
...
Issue gh-9631
4 years ago
Marcus Da Coregio
039e0328e1
Simplify Java Configuration RequestMatcher Usage
...
If Spring MVC is present in the classpath, use MvcRequestMatcher by default. This commit also adds a new securityMatcher method in HttpSecurity
Closes gh-11347
Closes gh-9159
4 years ago
Daniel Garnier-Moiroux
bf59d7c374
Update What's New for 5.8
4 years ago
Steve Riesenberg
46696a9226
CsrfTokenRequestHandler extends CsrfTokenRequestResolver
...
Closes gh-11896
4 years ago
Rob Winch
d94677f87e
CsrfTokenRequestAttributeHandler -> CsrfTokenRequestHandler
...
This renames CsrfTokenRequestAttributeHandler to CsrfTokenRequestHandler and
moves usage from CsrfFilter into CsrfTokenRequestHandler.
Closes gh-11892
4 years ago
Marcus Da Coregio
983ca6ea27
Update What's New for 5.8
4 years ago
Steve Riesenberg
8f44f74d44
Update What's New for 5.8
4 years ago
Steve Riesenberg
70eea8dc67
Update What's New for 5.8
4 years ago
Steve Riesenberg
355ef21117
Polish gh-11665
4 years ago
ch4mpy
1efb63387f
Add authentication converter for introspected tokens
...
Adds configurable authentication converter for resource-servers with
token introspection (something very similar to what
JwtAuthenticationConverter does for resource-servers with JWT decoder).
The new (Reactive)OpaqueTokenAuthenticationConverter is given
responsibility for converting successful token introspection result
into an Authentication instance (which is currently done by a private
methods of OpaqueTokenAuthenticationProvider and
OpaqueTokenReactiveAuthenticationManager).
The default (Reactive)OpaqueTokenAuthenticationConverter, behave the
same as current private convert(OAuth2AuthenticatedPrincipal principal,
String token) methods: map authorities from scope attribute and build a
BearerTokenAuthentication.
Closes gh-11661
4 years ago
Rob Winch
5ae492b1c1
Add What's New @WithMockUser Supported as Merged Annotation
4 years ago
Steve Riesenberg
86fbb8db07
Add new interfaces for CSRF request processing
...
Issue gh-4001
Issue gh-11456
4 years ago
Underground Hill
8b74bf9742
Updated reference to architecture page
...
In the context of Servlet Authentication page, "Architecture" should probably link to "Servlet Authentication Architecture" page
4 years ago
he1ex-tG
568277f8bc
Mistake in Kotlin code representation is fixed
4 years ago
Josh Cummings
0f58620643
Add AspectJ AuthorizationManager Support
...
Closes gh-11326
4 years ago
Josh Cummings
070dce1baf
Document ReactiveMethodSecurity improvements
...
Issue gh-9401
4 years ago
Josh Cummings
27ce5936cf
Add Caveat about Spring Security's co-routine support
...
Closes gh-10920
4 years ago
Rob Winch
89f8310d6c
Add Explicit SessionAuthenticationStrategy Option
...
SessionAuthenticationFilter requires accessing the HttpSession to do its
job. Previously, there was no way to just disable the
SessionAuthenticationFilter despite the fact that
SessionAuthenticationStrategy is invoked by the authentication filters
directly.
This commit adds an option to disable SessionManagmentFilter in favor of
requiring explicit SessionAuthenticationStrategy invocation already
performed by the authentication filters.
Closes gh-11455
4 years ago
jujunChen
13feb87171
Modify words
...
- <dependencyManagement> to dependencyManagement
- pom.xml to build.gradle
4 years ago