Marcus Da Coregio
7be2eb05d5
Merge branch '5.7.x' into 5.8.x
3 years ago
Marcus Da Coregio
cd4ddde779
Merge branch '5.6.x' into 5.7.x
3 years ago
Daniel Garnier-Moiroux
26bb60c567
Add rncToXsd task description to CONTRIBUTING.adoc
3 years ago
Rob Winch
6d56af7b65
SessionManagementDsl.requireExplicitAuthenticationStrategy
3 years ago
Josh Cummings
f054505d6d
Support Deferred Contexts
...
Closes gh-11817
Issue gh-10913
3 years ago
Daniel Garnier-Moiroux
93250013e4
Make X-Xss-Protection configurable through ServerHttpSecurity
...
OWASP recommends using "X-Xss-Protection: 0". The default is currently
"X-Xss-Protection: 1; mode=block". In 6.0, the default will be "0".
This commits adds the ability to configure the xssProtection header
value in ServerHttpSecurity.
This commit deprecates the use of "enabled" and "block" booleans to
configure XSS protection, as the state "!enabled + block" is invalid.
This impacts HttpSecurity.
Issue gh-9631
3 years ago
Steve Riesenberg
7b1158ddb7
Merge branch '5.7.x' into 5.8.x
3 years ago
Steve Riesenberg
70c61dc1dd
Merge branch '5.6.x' into 5.7.x
3 years ago
Dan Allen
c44230ba24
switch to offical Antora plugin for Gradle
...
- lock version to latest release of Antora 3.1
- rename properties on extension block
- use Node.js version provided by plugin
- remove package.json file
- assign environment variables using environments property on extension block
- use single quotes where possible in build script
- use default setting for log format
3 years ago
Marcus Da Coregio
cf3349f31a
Configure ContentNegotiationStrategy in HttpSecurityConfiguration
...
Closes gh-11916
3 years ago
Josh Cummings
506e50bfd0
Move Saml2 Authentication Filters
...
Issue gh-8819
3 years ago
Steve Riesenberg
bbac85e20b
Reduce severity of invalid registrationId to warn
...
This prevents filling the log file with error messages when routine
scans are being performed.
Closes gh-11344
3 years ago
Josh Cummings
ae6fb8c681
Add Deprecated Versions of Original Classes
...
Issue gh-7349
3 years ago
Josh Cummings
37a160245f
Adjust OAuth2 Resource Server packaging
...
Closes gh-7349
3 years ago
Steve Riesenberg
46696a9226
CsrfTokenRequestHandler extends CsrfTokenRequestResolver
...
Closes gh-11896
3 years ago
Steve Riesenberg
d140d95305
Fix assertion in NullSecurityContextRepository
...
Issue gh-11060
3 years ago
Steve Riesenberg
5d757919a2
Add SecurityContextHolderStrategy to new repository
...
In 6.0, RequestAttributeSecurityContextRepository will be the default
implementation of SecurityContextRepository. This commit adds the
ability to configure a custom SecurityContextHolderStrategy, similar
to other components.
Issue gh-11060
Closes gh-11895
3 years ago
Rob Winch
d94677f87e
CsrfTokenRequestAttributeHandler -> CsrfTokenRequestHandler
...
This renames CsrfTokenRequestAttributeHandler to CsrfTokenRequestHandler and
moves usage from CsrfFilter into CsrfTokenRequestHandler.
Closes gh-11892
3 years ago
Evgeniy Cheban
c1d27612af
Simplify AuthorizationManager composition
...
Closes gh-11625
3 years ago
Josh Cummings
3f8503f1b4
Deprecate AccessDecisionManager et al
...
Closes gh-11302
3 years ago
Marcus Da Coregio
983ca6ea27
Update What's New for 5.8
3 years ago
Marcus Da Coregio
0c96989cbe
Move script tag into body element
...
Closes gh-11879
3 years ago
github-actions[bot]
9564f1b5e4
Next development version
3 years ago
github-actions[bot]
dcbe900ff8
Release 5.8.0-M3
3 years ago
Steve Riesenberg
e4e24c6639
Update org.springframework to 5.3.23
...
Closes gh-11851
3 years ago
Steve Riesenberg
eeb152cd6d
Update htmlunit-driver to 2.64.0
...
Closes gh-11850
3 years ago
Steve Riesenberg
0159e8c976
Update org.mockito to 4.8.0
...
Closes gh-11849
3 years ago
Steve Riesenberg
e2a4227c11
Update junit-bom to 5.9.0
...
Closes gh-11848
3 years ago
Steve Riesenberg
573a5b626d
Update hsqldb to 2.7.0
...
Closes gh-11847
3 years ago
Steve Riesenberg
5d8427a52b
Update hibernate-entitymanager to 5.6.11.Final
...
Closes gh-11846
3 years ago
Steve Riesenberg
ece5ff1500
Update org.eclipse.jetty to 9.4.49.v20220914
...
Closes gh-11845
3 years ago
Steve Riesenberg
870de424f0
Update htmlunit to 2.64.0
...
Closes gh-11844
3 years ago
Steve Riesenberg
a884e0dda9
Update io.rsocket to 1.1.3
...
Closes gh-11843
3 years ago
Steve Riesenberg
6d3e04184b
Update io.projectreactor to 2020.0.23
...
Closes gh-11841
3 years ago
Steve Riesenberg
3d4f947cd5
Update mockk to 1.12.8
...
Closes gh-11840
3 years ago
Steve Riesenberg
d915f0f9ca
Update aspectj-plugin to 6.5.1
...
Closes gh-11839
3 years ago
Steve Riesenberg
a799528679
Update com.nimbusds to 9.43.1
...
Closes gh-11838
3 years ago
Steve Riesenberg
40a343c6e1
Update jackson-bom to 2.13.4
...
Closes gh-11835
3 years ago
Steve Riesenberg
67a00bcaa0
Fix JSONObject and JSONArray imports in tests
3 years ago
Steve Riesenberg
11f46fc584
Exclude release candidate dependencies
3 years ago
Marcus Da Coregio
9a4b39e823
Merge branch '5.7.x' into 5.8.x
3 years ago
Marcus Da Coregio
e01b43f0e4
Merge branch '5.6.x' into 5.7.x
3 years ago
Jerome Prinet
8d2fb6858f
Update Gradle Enterprise plugin to 3.11.1
3 years ago
Marcus Da Coregio
53ed6c3138
Merge branch '5.7.x' into 5.8.x
...
Closes gh-11825
3 years ago
Marcus Da Coregio
b6a8c10d05
Merge branch '5.6.x' into 5.7.x
...
Closes gh-11824
3 years ago
Marcus Da Coregio
7756247c3a
Simplify checkSamples task
...
Closes gh-11814
3 years ago
Steve Riesenberg
8f44f74d44
Update What's New for 5.8
3 years ago
Daniel Garnier-Moiroux
bea7761a1c
ClientRegistrations#rest defines 30s connect and read timeouts
3 years ago
Steve Riesenberg
70eea8dc67
Update What's New for 5.8
3 years ago
slam
45bbd86f7e
HttpSecurityDsl should support apply method
...
Closes gh-11754
3 years ago