Rob Winch
d079044592
SEC-2531: AuthenticationConfiguration#lazyBean should use BeanClassLoader
12 years ago
Rob Winch
e4a58375cc
SEC-2515: Detect object cycle for AuthenticationManager configuration
12 years ago
Rob Winch
4cdeacc277
SEC-2499: Allow MethodSecurityExpressionHandler in parent context
...
Previously a NoSuchBeanDefintionException was thrown when the
MethodSecurityExpressionHandler was defined in the parent context. This
happened due to trying to work around ordering issues related to SEC-2136
This commit resolves this by not marking the
MethodSecurityExpressionHandler bean as lazy unless it exists.
12 years ago
Rob Winch
9988fa141c
Update Spring Security version in pom.xml
12 years ago
Rob Winch
6be4e3a9fc
SEC-2506: Remove Bundlor Support
12 years ago
Rob Winch
04a527d4ec
SEC-2495: CSRF disables logout on GET
12 years ago
Rob Winch
7f99a2dfbb
SEC-2487: Update to Spring 3.2.8.RELEASE
12 years ago
Rob Winch
85305050c0
SEC-2455: Fix XML default login generation
12 years ago
Rob Winch
8a3a7961cb
SEC-2492: ExpressionUrlAuthorizationConfigurer private interceptUrl to void
12 years ago
Rob Winch
bf2df220ca
SEC-2490: LdapAuthenticationProviderConfigurer allows custom LdapAuthoritiesPopulator
12 years ago
Rob Winch
7a3da28987
SEC-2479: Search parent context for AuthenticationManager
12 years ago
Rob Winch
6c35c33abe
SEC-2447: Fix AuthenticationManagerBuilder ordering issues
12 years ago
Rob Winch
c42e13c966
loginProcessing test
12 years ago
Rob Winch
6b42a2eae1
SEC-2461: Multi WebSecurityConfiguration does not create null springSecurityFilterChain
12 years ago
Rob Winch
ec8b48150d
SEC-2474: Update poms
12 years ago
Rob Winch
8d8475deb1
SEC-2455: form-login@login-processing-url & logout@logout-url use matchers
...
Remove the deprecation warnings of using setFilterProcessingUrl by invoking
the matcher methods instead.
12 years ago
Rob Winch
1f833b0d6b
Add ExpressionUrlAuthorizationCOnfigurer tests
...
- Demo custom expression root
- Demo @Bean in expression example
12 years ago
Rob Winch
994117ad75
SEC-2436: Fix CsrfConfigurerNoWebMvcTests
12 years ago
Rob Winch
b7041ed00e
SEC-2436: Add @EnableWebMvcSecurity
12 years ago
Rob Winch
053c890a69
SEC-2450: WebSecurityConfigurerAdapter have default Order of 100
12 years ago
Rob Winch
2df5541905
SEC-2448: Update to HSQL 2.3.1
12 years ago
Rob Winch
04fac30d75
SEC-2449: <ldap-server> default port should fallback to dynamic value
12 years ago
Rob Winch
54ffa28bde
remove apacheDSWorkDir since custom tmp dir is created
12 years ago
Rob Winch
a34178bc40
SEC-2434: Update to Spring 3.2.6 and Spring 4.0 GA
12 years ago
Rob Winch
aaa7cec32e
SEC-2326: CsrfRequestDataValueProcessor implements RequestDataValueProcessor
...
Previously there was unecessary complexity in CsrfRequestDataValueProcessor
due to the non-passive changes in RequestDataValueProcessor. Now it simply
implements the interface with the methods for both versions of the interface.
This works since linking happens at runtime.
12 years ago
Rob Winch
7f714ebb23
SEC-2422: Session timeout detection with CSRF protection
12 years ago
Rob Winch
00d668dc5c
SEC-2431: UrlAuthorizationConfigurer missing <HttpSecurity> in doc
12 years ago
Rob Winch
4460e84b29
Updates to pom.xml author and repo
12 years ago
Rob Winch
8e8bdad8e6
SEC-2386: Remove stack for AuthenticationManagerBuilder with no authenticationProviders
12 years ago
Rob Winch
f2fdc9d1f5
SEC-2425: Add Test for EnableGlobalMethodSecurity works on parent config
12 years ago
Rob Winch
595b16d836
SEC-2377: Fix tests
12 years ago
Rob Winch
2a632a061e
SEC-2377: Hhandle EnableWebSecurity in both child & parent ApplicationContext
12 years ago
Rob Winch
0b996c669f
SEC-2424: Document ObjectPostProcessor
12 years ago
Rob Winch
13c5af5b91
SEC-2407: Better error message for missing securityFilterChainBuilders
12 years ago
Rob Winch
c7b93e6cee
SEC-2404: Fix CSRF config tests
12 years ago
Rob Winch
9dbe30c81d
SEC-2165: remember-me@token-validity-seconds can be parameterized
12 years ago
Rob Winch
afddb5eb39
SEC-2373: Update XSD doc to state security="none"
12 years ago
Rob Winch
6382b6341a
SEC-2355: Add test to validate intercept-url PATCH works
12 years ago
Collin Peters
85cd5627b6
SEC-2355: Add PATCH to intercept-url xsd
12 years ago
Rob Winch
2c8946c406
Next development version
12 years ago
Spring Buildmaster
9c703a3051
Release version 3.2.0.RC2
12 years ago
Rob Winch
dc317b3602
WebSecurityConfigurerAdapter implements WebSecurityConfigurer
12 years ago
Rob Winch
cda23443ac
XsdDocumentedTests now uses asciidoc instead of asciidoctor
12 years ago
Rob Winch
26be54653b
SEC-2382: AutowireBeanFactoryObjectPostProcessor works w/ BeanNameAutoProxyCreator
12 years ago
Rob Winch
9e7fbf8067
SEC-2321: Refine to use X-Requested-With: XMLHttpRequest
12 years ago
Rob Winch
5f290ba10f
SEC-2371: Remove ObjectPostProcessor.QUIESENT_POSTPROCESSOR
12 years ago
Rob Winch
604c26eb0d
Shis simplifies the class hieararchy significantly.EC-2366: Extract AbstractRequestMatcherRegistry from AbstractRequestMatcherConfigurer
...
This simplifies the class hierarchy significantly.
12 years ago
Rob Winch
348e3a22b6
SEC-2365: registerAuthentication->configure
12 years ago
Rob Winch
0978c12c47
SEC-2361: Java Config Sampels use @Autowired AuthenticationManagerBuilder
12 years ago
Rob Winch
0b0e7dbea9
SEC-2359: Merge DefaultLoginPageViewFilter w/ DefaultLoginPageGeneratingFilter
12 years ago