Josh Cummings
d169d5a835
Add AuthorizeReturnObject
...
Closes gh-14597
2 years ago
Josh Cummings
c611b7e33b
Add AuthorizationProxyFactory Reactive Support
...
Issue gh-14596
2 years ago
Josh Cummings
f541bce492
Polish AuthorizationAdvisorProxyFactory
...
- Ensure Reasonable Defaults
- Simplify Construction
Issue gh-14596
2 years ago
Steve Riesenberg
77c30c431e
Polish tests
...
Issue gh-11783
Issue gh-13763
2 years ago
Steve Riesenberg
80a8d3831a
Simplify reactive OAuth2 Client configuration
...
Closes gh-13763
2 years ago
Josh Cummings
52dfbfb5b3
Add Authorization Proxy Support
...
Closes gh-14596
2 years ago
Steve Riesenberg
d6382b83dc
Configure token-exchange via a bean
...
Issue gh-5199
Issue gh-11783
Closes gh-14701
2 years ago
Josh Cummings
bade66e588
Fix Circular Dependency
...
Closes gh-14674
2 years ago
Marcus Hert Da Coregio
f8ff056eb6
Update Max Sessions on WebFlux
...
Delete WebSessionStoreReactiveSessionRegistry.java and gives the responsibility to remove the sessions from the WebSessionStore to the handler
Issue gh-6192
2 years ago
Marcus Hert Da Coregio
a5ce8ae87f
Polish Max Sessions on WebFlux
...
This commit changes the PreventLoginServerMaximumSessionsExceededHandler to invalidate the WebSession in addition to throwing the error, this is needed otherwise the session would still be saved with the security context. It also changes the SessionRegistryWebSession to first perform the operation on the delegate and then invoke the needed method on the ReactiveSessionRegistry
Issue gh-6192
2 years ago
Josh Cummings
c639d0a514
Add AOP Integration Test
...
Closes gh-14637
2 years ago
Josh Cummings
4d383023cb
Add meta-annotation parameter support
...
Closes gh-14480
2 years ago
Josh Cummings
27cd9fa86c
Don't Use Deprecated Class
...
Issue gh-14628
2 years ago
DingHao
45c37c4454
Remove duplicate setSecurityContextHolderStrategy
...
Closes gh-14592
2 years ago
Rob Winch
750cb30ce4
Add AuthenticationTrustResolver.isAuthenticated
2 years ago
Josh Cummings
2702a64be7
Use Localhost for Internal Logout Endpoint
...
Closes gh-14553
2 years ago
Josh Cummings
3ab323663a
Do Not Wire Default OidcSessionStrategy without OidcLogoutConfigurer
...
Closes gh-14558
2 years ago
Marcus Hert Da Coregio
ccb2f06d0d
Partially revert fc658d10
...
OpenIDAuthenticationFilter exists in versions < 6.0
Issue gh-14531
2 years ago
DingHao
fc658d10d3
fix security filter sort in javadoc
...
Closes gh-14531
2 years ago
Marcus Hert Da Coregio
915d68e216
Remove includeExpiredSessions parameter
...
The reactive implementation of max sessions does not keep track of expired sessions, therefore we do not need such parameter
Issue gh-6192
2 years ago
Josh Cummings
7c3a6a567e
Fix Compilation Errors
...
Issue gh-14525
2 years ago
Andreas Asplund
07e0b1dc37
Saml2 LogoutFilter Is Placed Before Common LogoutFilter
...
Closes gh-14525
2 years ago
Josh Cummings
3a53422478
Fix Failing Test
...
Closes gh-14467
2 years ago
Josh Cummings
27ebeefb14
Fix Failing Test
...
Closes gh-14467
2 years ago
y-tomida
bdc0bd6b78
Add usernameParameter and passwordParameter to FormLoginDsl
...
Closes gh-14474
2 years ago
DingHao
3f65f600de
Use AuthorizationEventPublisher Bean
...
- For Jsr250MethodInterceptor and SecuredMethodInterceptor
Closes gh-14401
2 years ago
Marcus Hert Da Coregio
e2bab7b7ef
Add .serialized suffix and consider them as binary in Git
...
Issue gh-3737
2 years ago
Marcus Hert Da Coregio
4fb6a33d36
Verify Serializable Objects Are Deserializable Between Minor Versions
...
This commit introduces a test that verifies that Spring Security domain classes that implements Serializable and have the same serialVersionUID as SpringSecurityCoreVersion#SERIAL_VERSION_UID can be deserialized between minor versions.
This commit also introduces another test that should be used to generate the files containing the serialized content of the objects.
Closes gh-3737
2 years ago
Steve Riesenberg
16dc6be3c8
Update copyright year
...
Issue gh-14329
2 years ago
Geir Hedemark
c88aaedb48
Updated broken documentation link in javadocs
2 years ago
Marcus Hert Da Coregio
92af758f1f
Make springSecurityHandlerMappingIntrospectorBeanDefinitionRegistryPostProcessor passive
...
Instead of excluding the bean from AOT processing, we avoid redefining the beans if they are present or in the expected state.
Issue gh-14362
2 years ago
Marcus Hert Da Coregio
778a63a763
Revert "Exclude SpringSecurityHandlerMappingIntrospectorBeanDefinitionRegistryPostProcessor from AOT processing"
...
This reverts commit 8a93178da7 .
2 years ago
DingHao
7cd626fe25
Fix FilterChainProxy cannot be found when @EnableWebSecurity(debug = true)
...
Closes gh-14370
2 years ago
Marcus Hert Da Coregio
364bc10e78
Add hints for CompositeFilterChainProxy
...
Closes gh-14359
2 years ago
Marcus Hert Da Coregio
8a93178da7
Exclude SpringSecurityHandlerMappingIntrospectorBeanDefinitionRegistryPostProcessor from AOT processing
...
Closes gh-14362
2 years ago
Taehong Kim
ec02c22459
Add Request Path Extraction Support
...
Closes gh-13256
2 years ago
Yan Kardziyaka
99218db84a
Add order offset to @EnableMethodSecurity
...
Closes gh-13214
2 years ago
Josh Cummings
e058b559b8
Polish Method Security Eager-Loading
...
Issue gh-11596
2 years ago
Josh Cummings
9a5d991383
Address eager-loading of infrastructure beans
...
Closes gh-11596
2 years ago
Josh Cummings
33800c0124
Address eager-loading of infrastructure beans
...
Closes gh-11596
2 years ago
Josh Cummings
fc007aa373
Check OpenSAML Version in XML Support
...
Closes gh-12483
2 years ago
Josh Cummings
eaaa813ede
Fix header value typo
...
Closes gh-11948
2 years ago
Josh Cummings
8a34e32a24
Polish IpAddressAuthorizationManager
...
Closes gh-10577
2 years ago
brunodmartins
ea7c720ce7
Add hasIpAddress to Kotlin DSL
...
Closes gh-10577
2 years ago
Rob Winch
142b268a21
Use CompositeFilterChainProxy
...
By extending FilterChainProxy CompositeFilterChainProxy is more passive since
users often depend on the type of the springSecurityFilterChain Bean being
FilterChainProxy (even though it can already be other types - when debug is
enabled).
Issue gh-14128
2 years ago
Rob Winch
70dfb3d391
Add HandlerMappingIntrospector Caching
...
Closes gh-14128
2 years ago
Marcus Da Coregio
57ab15127a
Add Max Sessions on WebFlux
...
Closes gh-6192
2 years ago
DerChris173
e6bea1cfa1
Polish RoleHierarchy Bean Usage
...
Issue gh-12783
2 years ago
kandaguru17
b76f7c029d
Use available RoleHierachy Bean for MethodSecurity Config
...
Closes gh-12783
2 years ago
Josh Cummings
bb6b55aca3
Add Not Support
...
Closes gh-14058
2 years ago