Marcus Da Coregio
933b302979
Fix once-per-request="true" not taking any effect
...
Closes gh-13491
3 years ago
Josh Cummings
8d0e426654
Generate Shared Test SAML Response
...
Issue gh-13433
3 years ago
Josh Cummings
f2f19270da
Update to OpenSAML 4.3.0
...
Closes gh-13433
3 years ago
Marcus Da Coregio
a0540f5c65
Deprecate AbstractConfiguredSecurityBuilder#apply
...
Closes gh-13436
3 years ago
Marcus Da Coregio
1ff5eb6b57
Add with() method to apply SecurityConfigurerAdapter
...
This method is intended to replace .apply() because it will not be possible to chain configurations when .and() gets removed
Closes gh-13204
3 years ago
Josh Cummings
1abfd2c801
Only Register as Advisor in Proxy Mode
...
Now that https://github.com/spring-projects/spring-framework/issues/30689
is addressed.
Closes gh-13198
3 years ago
Marcus Da Coregio
618847418f
Automatically enable .cors() if CorsConfigurationSource bean is present
...
Closes gh-5011
3 years ago
Claudio Nave
52e12ad64b
Replace deprecated methods
3 years ago
Marcus Da Coregio
8efdc5c926
Polish Contribution
...
Issue gh-13215
3 years ago
kandaguru17
401058d5ff
Implemented AuthorizeHttpRequestsConfigurer to consider GrantedAuthorityDefaults for custom rolePrefix
...
Closes gh-13215
3 years ago
Evgeniy Cheban
c5461b17de
EnableMethodSecurity annotation does not get imported when defined as a meta-annotation
...
Closes gh-12870
3 years ago
Josh Cummings
208fb62db9
Update Deprecated Usage
...
Issue gh-12629
3 years ago
Krzysztof Krason
9b603b99ab
Using modern Java features
3 years ago
Kandaguru17
7e01ebdd92
Remove LazyCsrfTokenRepository usage
...
Closes gh-13194
3 years ago
Josh Cummings
fb910e2997
Prepare for Spring Security 6.2
...
Closes gh-14316
3 years ago
Marcus Da Coregio
2686af0c4d
Revert "Only Register as Advisor in Proxy Mode"
...
This reverts commit 35ad1f85
3 years ago
Marcus Da Coregio
7250abc185
Does not apply a Configurer when disabled from another DSL
...
Closes gh-13203
3 years ago
Marcus Da Coregio
537e10cf9c
Improve javadoc adding how to stick with defaults and link to documentation
...
Closes gh-13273
3 years ago
Josh Cummings
f566ed0afd
Update Symlink for 6.1
...
Issue gh-13131
3 years ago
Josh Cummings
71703dc371
Update Symlink for 6.0
...
Issue gh-13131
3 years ago
Josh Cummings
73cb9862ad
Update Symlink for 5.8
...
Issue gh-13131
3 years ago
Josh Cummings
1eefd433b6
Add spring-security.xsd symlink
...
Closes gh-13131
3 years ago
Josh Cummings
35ad1f857e
Only Register as Advisor in Proxy Mode
...
Closes gh-13160
3 years ago
lukasz.migdalek
f4915890cc
Use Spec Order for Verifying Signatures
...
Closes gh-12346
3 years ago
Josh Cummings
e9a02bc6e9
RememberMeConfigurer Picks Up SecurityContextRepository
...
Closes gh-13104
3 years ago
Marcus Da Coregio
69338ecdfa
Only Observe AuthenticationManager if it is not null
...
Closes gh-13084
3 years ago
SeasonPan
a44e91d044
fix javadoc typo
3 years ago
Ruslan Stelmachenko
caa4093619
Fix javadoc for migration from WebSecurityConfigurerAdapter
3 years ago
Josh Cummings
1e25756ee6
Fix Import Order
3 years ago
Josh Cummings
64542b4059
Polish X509 SecurityContextRepository
...
Like Basic and Bearer authentication, X509 is
stateless by default. As such, it is better to not
pick up the global SecurityContextRepository bean.
The better fix is to change the default from
HttpSessionSecurityContextRepository to
RequestAttributeSecurityContextRepository.
Issue gh-13008
3 years ago
Josh Cummings
c3479ddb45
Pick Up SecurityContextRepository
...
Closes gh-13008
3 years ago
Marcus Da Coregio
2d52fb8e4b
Clear Repository on Logout
3 years ago
Marcus Da Coregio
82a149207d
Deprecate .and() and non lambda DSL methods
...
Closes gh-12629
3 years ago
Marcus Da Coregio
54117d7d27
Fix test suffix to align with checkstyle
3 years ago
Marcus Da Coregio
01d1e20dc3
Deprecate shouldFilterAllDispatcherTypes
...
Closes gh-12138
3 years ago
Martin Tarjányi
5eefe9dcff
Fix typo in SessionManagementConfigurer javadoc
3 years ago
twosom
cbb4e40166
fix typo in RequestCacheResultMatcher
3 years ago
Josh Cummings
a4bc0a6f3c
Polish
...
- Add POST /login assertion
- Rearrange test and config class
Issue gh-12552
3 years ago
Clayton Walker
e2332d9620
Add disable to FormLoginDsl
...
Closes gh-12552
3 years ago
Josh Cummings
a7562ad950
Update io.spring.javaformat to 0.0.38
...
Closes gh-12891
3 years ago
Josh Cummings
3ad6c6ce06
Use EntityId-lookup Components
...
Closes gh-12880
3 years ago
Josh Cummings
46452c0cae
Add saml2Metadata
...
Closes gh-11828
3 years ago
hdeadman
e0284a4503
Fix CAS packages for 4.0.1 and Jasig references
...
Issue gh-11674
3 years ago
hdeadman
b4d3ac6665
Revert "Remove CAS module"
...
This reverts commit caf4c471
3 years ago
Josh Cummings
bbd31f0e33
Defer ObservationRegistry Lookup
...
Closes gh-12780
3 years ago
Marcus Da Coregio
1c3ce1e401
Fix entity-id ignored in RelyingPartyRegistration XML config
...
Closes gh-11898
3 years ago
Leonid Rozenblyum
000b4bc495
Fix NPE in HttpSecurity#addFilterBefore, HttpSecurity#addFilterAfter
...
Before the fix, these methods would throw a NPE in case when the filter class passed as the second parameter, is not registered yet.
In particular, this exception can occur when mixing standard and custom DSL to register filters.
The fix doesn't change the situation that standard DSL for registration of filters cannot refer to filters that are registered via custom DSL even though those calls were done earlier.
It just provides more user-friendly error handling for this and most likely other scenarios of calls of HttpSecurity#addFilterBefore, HttpSecurity#addFilterAfter.
The error handling is implemented similarly to HttpSecurity#addFilter.
Closes gh-12637
3 years ago
twosom
cef13a6a16
Fix Javadoc Type Parameter
3 years ago
twosom
c79dac49ca
Fix Typo
3 years ago
Tobias Meurer
7dd5cc6082
Pick Up Custom SecurityContextRespository
...
Closes gh-12579
3 years ago