Ben Alex
ee78570902
Prepare to release 1.0.0 RC2.
20 years ago
Ben Alex
a5000972fb
Add RC1.
20 years ago
Ben Alex
079e22e5d8
Refer to 1.0.0 release work in progress.
20 years ago
Ben Alex
edf3b466c4
Fix so multiproject:site doesn't fail.
20 years ago
Ben Alex
54aaefa703
Move changelog for 0.9.0 to JIRA after adding the tasks previously in changes.xml.
20 years ago
Mark St. Godard
9b898e84c4
Added Java 5 Annotations version of Contacts sample (contacts-tiger).
...
Note: I have added a pre goal to add the source dir of the original Contacts example.
I also added an exclude on the main project.properties for the attributes sample, as the Commons Attributes plugin causes issues with Java 5 source compilation.
The Annotations version will eventually replace the Commons Attributes approach, for now those users will need to manually build the attributes example.
21 years ago
Ben Alex
f5741962ed
Add createSessionAllowed property, which should be set to false to avoid unnecessary session creation.
21 years ago
Ben Alex
35ca25f085
BasicAuthenticationProcessingFilter no longer creates HttpSession via WebAuthenticationDetails call.
21 years ago
Ben Alex
55f5c3397a
Relocated JdbcDaoExtendedImpl.convertAclObjectIdentityToString to superclass (pursuant to suggestion made by Tim Kettering on acegisecurity-developer).
21 years ago
Ben Alex
e805aa2e73
Add annotation support.
21 years ago
Mark St. Godard
ec5e39c2e8
Initial checkin of user security context switching (see SEC-15). This is the first cut of the SwitchUserProcessingFilter that handles switching to a target uesr and exiting back to the original user. Note: This is going to be used for the common use-case of an Administrator 'switching' to another user (i.e. ROLE_ADMIN -> ROLE_USER). This is the initial cut of a Unix 'su' for Acegi managed web applications.
21 years ago
Scott McCrory
c2c48b905b
Added package.html files to reamining java packages (see http://opensource.atlassian.com/projects/spring/browse/SEC-41 )
21 years ago
Scott McCrory
f4c8211cc2
Replaced .cvsignore placeholders for package.html files (which also serve some doccumentary purpose).
21 years ago
Scott McCrory
db4ed4bc44
Added debug statement to AbstractTicketValidator to help with Acegi+CAS+SSL setup (thanks Seth Ladd for the patch) (see http://opensource.atlassian.com/projects/spring/browse/SEC-34 )
21 years ago
Scott McCrory
c66c5dfab5
AuthorizeTag no longer depends on JDK 1.4. Tested on Websphere 5.0 w/JDK 1.3 (see http://opensource.atlassian.com/projects/spring/browse/SEC-11 )
21 years ago
Ben Alex
f20bc6d9d0
Catch up with recent changes.
21 years ago
Ben Alex
f650289142
Avoid expense of HttpSession when working with anonymous users.
21 years ago
Ben Alex
c8275c591f
Reflect additional releases made for backporting SEC-20 security fix.
21 years ago
Ben Alex
3e4a29eae9
FilterSecurityInterceptor now has an observeOncePerRequest boolean property, allowing multiple fragments of the HTTP request to be individually authorized (see http://opensource.atlassian.com/projects/spring/browse/SEC-14 ).
21 years ago
Ben Alex
d09d250656
Form, CAS, X509 and Remember-Me authentication mechanisms now publish an InteractiveAuthenticationSuccessEvent (see http://opensource.atlassian.com/projects/spring/browse/SEC-5 ).
21 years ago
Ben Alex
60f8095cf2
Make Authenticated.isAuthenticated() behaviour switchable. See http://opensource.atlassian.com/projects/spring/browse/SEC-13 .
21 years ago
Ben Alex
ef8281f534
HttpSessionContextIntegrationFilter elegantly handles IOExceptions and ServletExceptions within filter chain (see http://opensource.atlassian.com/projects/spring/browse/SEC-20 ).
21 years ago
Ben Alex
a3d26edea3
JBoss container adapter to use getName() instead to toString() (see http://opensource.atlassian.com/projects/spring/browse/SEC-22 ).
21 years ago
Ben Alex
a312fede74
Refactor DAO authentication failure events under a consistent abstract superclass (thanks to Mark St Godard for suggestion).
21 years ago
Ben Alex
c0f1d4e19d
Remove getters and setters from JdbcDaoImpl so IoC container cannot modify MappingSqlQuerys (thanks to David Durham for bug report).
21 years ago
Ben Alex
a15691d9d7
Silently catch NotSerializableException in AbstractProcessingFilter if rootCause is not Serializable (thanks to Joseph Dane for reporting this bug).
21 years ago
Ben Alex
5f75e9bf9a
Refactor Authentication.isAuthenticated() handling to be more performance (as per developer list discussion).
21 years ago
Ben Alex
a7b5299e77
Correct synchronization issue with FilterToBeanProxy initialization (thanks to George Franciscus and Volker Malzahn as per acegisecurity-developer discussion 4 June 2005).
21 years ago
Ben Alex
c699f7d40e
Support non-username as primary key.
21 years ago
Ben Alex
4e55780e7c
Performance optimisations thanks to Paulo Neves.
21 years ago
Ben Alex
cfb8271826
Reorder DaoAuthenticationProvider exception logic as per developer list discussion.
21 years ago
Ben Alex
ecbfac2ff8
Made AclEntry Serializable (correct issue with BasicAclEntryCache).
21 years ago
Ben Alex
e08e66dec6
Refactor SecurityContextHolder to return a SecurityContext instead of Authentication.
21 years ago
Ben Alex
6a9abe5d90
Remove ContextHolder and introduce SecurityContext.
21 years ago
Luke Taylor
d4da559ccc
added entry for credential expiry modifications
21 years ago
Ben Alex
d169829f27
AbstractAuthenticationToken.getName() now returns username alone if UserDetails present.
21 years ago
Ray Krueger
6f286e2054
AuthorityGranter.grant now returns a java.util.Set of role names, instead of a single role name
21 years ago
Ben Alex
cff9ba4988
AnonymousProcessingFilter offers protected method to control when it should execute as per http://forum.springframework.org/viewtopic.php?p=19766 .
21 years ago
Ben Alex
a68d720e88
Prepare for 0.9.0.
21 years ago
Ben Alex
4cf500763f
Release 0.8.2.
21 years ago
Ben Alex
efd8955a3d
General update.
21 years ago
Ben Alex
fdf5c63033
Add obtainUsername method as per http://forum.springframework.org/viewtopic.php?t=4757 .
21 years ago
Ben Alex
2ee7cc1c18
General update.
21 years ago
Ben Alex
204da55a0b
PasswordDaoAuthenticationProvider no longer stores String against Authentication.setDetails().
21 years ago
Ray Krueger
9649003d57
AbstractProcessingFilter no longer uses a set*FailureUrl approach for every exception, it now uses a properties object that maps authenticationExceptions to failure urls
21 years ago
Ben Alex
684d5bc10e
Handle null Authentication.getAuthorities() in AuthorizeTag.
21 years ago
Ben Alex
8e6305ae81
Update commons-codec dependency to 1.3.
21 years ago
Ben Alex
8ae2276843
TokenBasedRememberMeServices changed to use long instead of int for tokenValiditySeconds.
21 years ago
Ben Alex
8884ca51af
Add credentialsExpiredFailureUrl getter/setter to AbstractProcessingFilter.
21 years ago
Ben Alex
747825cda1
Correct location of AuthenticationSimpleHttpInvokerRequestExecutor in clientContext.xml.
21 years ago