Luke Taylor
71ba977dad
Fix package name in manual code
12 years ago
Rob Winch
c411014c24
SEC-2533: Global AuthenticationManagerBuilder disables clearing child credentials
12 years ago
Rob Winch
cb0549a609
SEC-2498: RequestCache allows POST when CSRF is disabled
12 years ago
Rob Winch
d079044592
SEC-2531: AuthenticationConfiguration#lazyBean should use BeanClassLoader
12 years ago
Rob Winch
c0590e614a
SEC-2177: Polish
12 years ago
Maciej Zasada
7cf37856c0
SEC-2177: Striping off all leading schemes
...
Striping off all leading schemes in the DefaultRedirectStrategy, so it
will be less vulnerable to open redirect phishing attacks. More info can
be found at SEC-2177 JIRA issue.
12 years ago
Rob Winch
5be4bfd55e
SEC-2173: Polish javadoc
12 years ago
Rob Winch
2628be60d1
SEC-2173: Added SystemWideSaltSource.toString() test
12 years ago
Gamal Shaban
1c50a86661
SEC-2173: Override toString method in SystemWideSaltSource
...
Now prints the saltSource string instead of the object memory signature.
12 years ago
Julien Dubois
7325b97c76
SEC-2519: RememberMeAuthenticationException supports root cause
...
Added a constructor which keeps the root cause of the exception, and
added some documentation
12 years ago
Rob Winch
91a074c744
Merge pull request #62 from dalbertom/typo
...
Correct typo in AbstractRememberMeServices assertion
12 years ago
Alexander Kjäll
50637d4451
SEC-2518: UserDetailsService javadoc repeats "insensitive"
...
Typo in javadoc, "case insensitive" was repeated twice.
12 years ago
Rob Winch
a7005bd742
SEC-2500: Prevent anonymous bind for ActiveDirectoryLdapAuthenticator
12 years ago
Rob Winch
ea902e5829
SEC-2507: WebExpressionVoter.supports support subclasses of FilterInvocation
12 years ago
Rob Winch
e4a58375cc
SEC-2515: Detect object cycle for AuthenticationManager configuration
12 years ago
Rob Winch
32d3e29c65
SEC-2325: Polish CSRF Tag support
...
- Rename csrfField to csrfInput
- Make AbstractCsrfTag package scope
- rename FormFieldTag to CsrfInputTag
- rename MetaTagsTag to CsrfMetaTagsTag
- removed whitespace from tag output so output is
minimized & improving browser performance
- Update @since
- changed test names to be more meaningful
12 years ago
beamerblvd
a3e0475998
SEC-2325 Added JSP tags for CSRF meta tags and form fields
12 years ago
beamerblvd
26cee61b98
SEC-2335 Added ACL schema files for MySQL, SQL Server, Oracle
12 years ago
John Tims
56bb331760
SEC-2514: Fix typo in hellomvc.asc
...
packags -> packages
12 years ago
John Tims
1e3cdaf8a9
SEC-2513: Add link to SpringSource CLA form
12 years ago
Manimaran Selvan
1d6536fa71
SEC-2512: Fix typo in reference`
...
udates -> updates
12 years ago
Rob Winch
e15cee62f4
SEC-2511: Remove double ALLOW-FROM in X-Frame-Options header
12 years ago
getvictor
6de138c2f2
SEC-2511: Remove double ALLOW-FROM from X-Frame-Options header.
...
The interface documentation for getAllowFromValue states: Gets the value for ALLOW-FROM excluding the ALLOW-FROM.
12 years ago
Rob Winch
4cdeacc277
SEC-2499: Allow MethodSecurityExpressionHandler in parent context
...
Previously a NoSuchBeanDefintionException was thrown when the
MethodSecurityExpressionHandler was defined in the parent context. This
happened due to trying to work around ordering issues related to SEC-2136
This commit resolves this by not marking the
MethodSecurityExpressionHandler bean as lazy unless it exists.
12 years ago
Rob Winch
9988fa141c
Update Spring Security version in pom.xml
12 years ago
Rob Winch
8afa8d8588
Fix integration tests
12 years ago
Rob Winch
6dfdb10e31
Fix move to 4.0
12 years ago
Rob Winch
6be4e3a9fc
SEC-2506: Remove Bundlor Support
12 years ago
Rob Winch
04a527d4ec
SEC-2495: CSRF disables logout on GET
12 years ago
Rob Winch
de4ed136ea
Fix spring4 test
12 years ago
Rob Winch
4a1a2dfed4
Update min Spring version of 4.0.2.REELASE
12 years ago
Rob Winch
3fc9dd82f3
Start Spring Security 4.0.x
12 years ago
Spring Buildmaster
551f600073
Next development version
12 years ago
Rob Winch
f2cde4ffa3
SEC-2486: Update tests to Spring LDAP 2.0.1.RELEASE
12 years ago
Rob Winch
9810768186
SEC-2485: Update test to Spring 4.0.2.RELEASE
12 years ago
Rob Winch
7f99a2dfbb
SEC-2487: Update to Spring 3.2.8.RELEASE
12 years ago
Rob Winch
85305050c0
SEC-2455: Fix XML default login generation
12 years ago
Rob Winch
8a3a7961cb
SEC-2492: ExpressionUrlAuthorizationConfigurer private interceptUrl to void
12 years ago
Rob Winch
fc8e4868ce
SEC-2468: Fix tests
12 years ago
Rob Winch
65367e6547
SEC-2468: JdbcUserDetailsManager#createNewAuthentication uses null credentials
12 years ago
Rob Winch
bf2df220ca
SEC-2490: LdapAuthenticationProviderConfigurer allows custom LdapAuthoritiesPopulator
12 years ago
Rob Winch
152f41f61e
SEC-2392: KeyBasedPersistenceTokenService uses bytes instead of bits
...
The method setPseudoRandomNumberBits actually sets the number of bytes. This
commit deprecates setPseudoRandomNumberBits and adds
setPseudoRandomNumberBytes. The default value is still 256 to remain passive
but will be updated in 4.x.
12 years ago
Rob Winch
7a3da28987
SEC-2479: Search parent context for AuthenticationManager
12 years ago
Rob Winch
e17adad878
SEC-2469: Support Spring LDAP 2.0.1+
12 years ago
Luke Taylor
058b9debef
Minor slapd config changes
12 years ago
Rob Winch
6c35c33abe
SEC-2447: Fix AuthenticationManagerBuilder ordering issues
12 years ago
Rob Winch
c42e13c966
loginProcessing test
12 years ago
Rob Winch
6b42a2eae1
SEC-2461: Multi WebSecurityConfiguration does not create null springSecurityFilterChain
12 years ago
Rob Winch
ec8b48150d
SEC-2474: Update poms
12 years ago
Rob Winch
4eff50b48b
SEC-2474: Update tests against Spring 4.0.1
12 years ago