Rob Winch
|
5d94cd5e13
|
SEC-1735: Do not remove SecurityContext from HttpSession when anonymous Authentication is saved if original SecurityContext was anonymous
|
14 years ago |
Rob Winch
|
1f835fec43
|
SEC-1867: Perform null check on Authentication.getCredentials() prior to calling toString()
|
14 years ago |
Rob Winch
|
448a42916d
|
SEC-1880: Corrected error message when using both logout-success-url and success-handler-ref
|
14 years ago |
Rob Winch
|
ea56a98883
|
SEC-1868: Remove error level logs from SecurityNamespaceHandler when the web classes are not available and not required
To get the detailed errors the FilterChainProxy is loaded again in reportMissingWebClasses
and included in the readerContext fatal log.
|
14 years ago |
Rob Winch
|
6fe6e18939
|
SEC-1870: Updated HttpSessionDestroyedEvent to properly look for SecurityContexts as session attribute values instead of session attribute names
|
14 years ago |
Rob Winch
|
044861eb20
|
Renamed **/*Spec.groovy to **/*Tests.groovy to better follow conventions
|
14 years ago |
Rob Winch
|
8ca2927761
|
Renamed **/Test.java to **/Tests.java to better follow conventions
|
14 years ago |
Rob Winch
|
aabb16912f
|
SEC-1878: DefaultFilterChainValidator properly handles AccessDecisionManager throwing exceptions other than AccessDeniedException
|
14 years ago |
Luke Taylor
|
00936c6b49
|
Switch to post release snapshot version.
|
14 years ago |
Luke Taylor
|
9b423a7726
|
Set 3.1.0 release version.
|
14 years ago |
Luke Taylor
|
9fa6e78770
|
SEC-1857: Use Principal.getName() in ContextPropagatingRemoteInvocation
This is a better option than using the toString() method
where the latter doesn't return the username. e.g when the
principal is a UserDetails.
|
14 years ago |
Steffen Ryll
|
0de067ae63
|
SEC-1793: Added convenience constructor to DefaultSpringSecuritySontextSource
This makes it easier to configure more than one
LDAP URL (fail-over scenario).
|
14 years ago |
Rob Winch
|
999adbc6ee
|
SEC-1827: If use-secure-cookie is set to false explicitly set useSecureCookie to false on AbstractRememberMeServices
|
14 years ago |
Rob Winch
|
53483df1f5
|
SEC-1678: Added What's new section to reference
|
14 years ago |
Rob Winch
|
041cb1dcc3
|
SEC-1858: Included the updates for logout-success-url documentation
|
14 years ago |
Rob Winch
|
3dca70403d
|
Suppress compiler warnings and minor javadoc fix for ProviderManager
|
14 years ago |
Rob Winch
|
ff495b698e
|
SEC-1858: Removed methods for generating docbook for xsd
Not squashing so this is around if needed again
|
14 years ago |
Rob Winch
|
c8b847f1ed
|
SEC-1858: Added integration tests to validate that the xsd is documented in the reference
|
14 years ago |
Rob Winch
|
f88b6f75ff
|
SEC-1858: Overhall the namespace appendix of the reference to include missing elements and attributes
|
14 years ago |
Rob Winch
|
de397bc0ce
|
SEC-1858: Updated xsd documentation to have documentation for all elements/attributes and added documentation of default values where appropriate
|
14 years ago |
Dave Syer
|
8565116f20
|
SEC-1472: Add crypto wrappers for BCrypt
|
14 years ago |
Dave Syer
|
944d762da9
|
Add eclipse generated meta-inf to ignores
|
14 years ago |
Luke Taylor
|
3b13a3fb25
|
SEC-1812: Replace assertion with warning message when overriding the global AuthenticationManager.
|
14 years ago |
Luke Taylor
|
8e1d407e3e
|
SEC-1848: LDAP encode name when using user DN patterns in AbstractLdapAuthenticator.
|
14 years ago |
Luke Taylor
|
8fd2963e6b
|
Deprecate storage of Authentication object in AuthenticationException.
|
14 years ago |
Luke Taylor
|
b60367e30c
|
Upgrade to validater 4.2
|
14 years ago |
Luke Taylor
|
0bccbbfc18
|
SEC-1779: Make new getters protected rather than public.
|
14 years ago |
Luke Taylor
|
178765cf83
|
SEC-1836: Forgot taglib comment update.
|
14 years ago |
Luke Taylor
|
f456db267f
|
SEC-1779: Added getters for success and failure handlers to AbstractAuthenticationProcessingFilter.
|
14 years ago |
Luke Taylor
|
30088f19ae
|
SEC-1806: Log that bean definition is being created rather than bean in LdapServerBDP.
|
14 years ago |
Luke Taylor
|
09ac4bd8f9
|
SEC-1833: Remove unused securityContextClass from HttpSessionSecurityContextRepository.
|
14 years ago |
Luke Taylor
|
fc399af136
|
SEC-1836: use GET as the default method with authorize tag.
|
14 years ago |
Luke Taylor
|
2f67bb3032
|
SEC-1847: Add authentication-manager-ref attribute to http and global-method-security namespace elements.
|
14 years ago |
Luke Taylor
|
bce4d81142
|
Mark overriding "extraInformation" methods in account status exceptions as deprecated.
|
14 years ago |
Luke Taylor
|
c0c283029a
|
Upgrade Jetty version.
|
14 years ago |
Luke Taylor
|
44e2543015
|
Minor changes to make filter chain validation more robust with custom request matchers.
|
14 years ago |
Luke Taylor
|
f2786805e6
|
SEC-1841: Added request-matcher-ref attribute to namespace for defining a filter chain.
|
14 years ago |
Luke Taylor
|
58f7d3acc6
|
SEC-1835: Changed xsd:ID to xsd:token.
|
14 years ago |
Luke Taylor
|
f1e63f3008
|
SEC-1802: Add digits to valid URL scheme regex.
|
14 years ago |
Rob Winch
|
2fd0a65049
|
SEC-1839: Updated preauth example to use </security:authentication-manager> instead of </security-authentication-manager>
|
14 years ago |
Luke Taylor
|
ac6ed671a1
|
SEC-1830: Use constructor injection in namespace parsing code for creation of ProviderManager
|
14 years ago |
Luke Taylor
|
9d66e1fac3
|
Exclude static resources from filter chain in tutorial sample.
|
14 years ago |
Luke Taylor
|
2953f56b2b
|
Remove ancient code formatter artifacts.
|
14 years ago |
Luke Taylor
|
869c6a7c18
|
SEC-1800: Set input size to 30 for OpenID login.
|
14 years ago |
Luke Taylor
|
44364d0101
|
SEC-1826: Empty attribute list should be treated the same as null in DelegatingMethodSecurityMetadataSource.
|
14 years ago |
Luke Taylor
|
be8ee61f82
|
PreInvocationAuthorizationAdviceVoter was checking the wrong type in its "supports" method.
This isn't actually used, but is still incorrect.
|
14 years ago |
Luke Taylor
|
a573e7b395
|
SEC-1820: Added null check for attributesToFetch in OpenID4JavaConsumer.
|
14 years ago |
Rob Winch
|
4a000d040c
|
SEC-1815: Downgrade openid to use HttpClient 4.1.1 to avoid bug in openid4java's usage of HttpClient
|
14 years ago |
Luke Taylor
|
359bd7c468
|
SEC-1804: Updated Javadoc wrt immutability of User class.
|
15 years ago |
Luke Taylor
|
7bde24af6c
|
Reset version to 3.1.0.CI-SNAPSHOT.
|
15 years ago |