Steve Riesenberg
b91d38752a
Update com.nimbusds to 9.22
...
Closes gh-10713
4 years ago
Steve Riesenberg
9b12616913
Update jackson-bom to 2.13.1
...
Closes gh-10710
4 years ago
Steve Riesenberg
08139cf9f4
Update logback-classic to 1.2.10
...
Closes gh-10709
4 years ago
Steve Riesenberg
801dcfdcb4
Allow milestones and release candidates in version upgrades
4 years ago
Steve Riesenberg
4939331501
Fix inconsistency in hasProperty check
4 years ago
Steve Riesenberg
8abd4e999f
Add GitHubReleasePlugin with createGitHubRelease task
...
Closes gh-10456
Closes gh-10457
4 years ago
Josh Cummings
194eaf8491
Pull most recent Structure101 version
...
Closes gh-10696
4 years ago
Marcus Da Coregio
60ed3602f6
Make source code compatible with JDK 8
...
Closes gh-10695
4 years ago
Joe Grandja
214cfe807e
Allow Jwt assertion to be resolved
...
Closes gh-9812
4 years ago
heowc
1ab0705b47
Fix typo
4 years ago
Marcus Da Coregio
f04cd641b0
Fix @since tag
...
Issue gh-10590, gh-10554
4 years ago
Rob Winch
3bb82c4449
Antora prerelease: true for milestone and rc
4 years ago
Rob Winch
89366d0874
Update RELEASE.adoc for antora.yml
4 years ago
Rob Winch
6884a16726
Add CheckAntoraVersionPlugin
4 years ago
Josh Cummings
6b54afe9a3
Remove SAML 2.0 Logout Default
...
Closes gh-10607
4 years ago
Josh Cummings
b9453da343
Support No SingleLogoutServiceLocation
...
Closes gh-10674
4 years ago
Marcus Da Coregio
18427b6411
Configure WebInvocationPrivilegeEvaluator bean for multiple filter chains
...
Closes gh-10554
4 years ago
Marcus Da Coregio
7e17a00197
Add RequestMatcherEntry
4 years ago
Marcus Da Coregio
53b8cff26f
Introduce AuthorizationManagerWebInvocationPrivilegeEvaluator
...
Closes gh-10590
4 years ago
Josh Cummings
cd8983d4e5
Polish enableSessionUrlRewriting Clarification
...
Closes gh-7644
4 years ago
James Howe
5598688fa6
Clarify behaviour of enableSessionUrlRewriting
...
See #3087
4 years ago
Guirong Hu
22379e79e7
Fix the bug that the custom GrantedAuthority comparison fails
...
Closes gh-10566
4 years ago
Marcus Da Coregio
65426a40ec
Add Cross Origin Policies headers
...
Add DSL support for Cross-Origin-Opener-Policy, Cross-Origin-Embedder-Policy and Cross-Origin-Resource-Policy headers
Closes gh-9385, gh-10118
4 years ago
Steve Riesenberg
7ec3b55ab3
Fix Reactive OAuth2 Kotlin DSL examples
...
Closes gh-10580
4 years ago
Marcus Da Coregio
ed3b0fbaad
Prevent using both authorizeRequests and authorizeHttpRequests
...
Closes gh-10573
4 years ago
Steve Riesenberg
62e8799a8d
Use BDD in tests
4 years ago
Steve Riesenberg
df0f6f83af
Polish gh-9597
4 years ago
Karl Tinawi
925d531cbe
Set details on authentication token created by HttpServlet3RequestFactory
...
Currently the login mechanism when triggered by executing HttpServlet3RequestFactory#login does not set any details on the underlying authentication token that is authenticated.
This change adds an AuthenticationDetailsSource on the HttpServlet3RequestFactory, which defaults to a WebAuthenticationDetailsSource.
Closes gh-9579
4 years ago
Steve Riesenberg
074e38d565
Add missing since
...
Issue gh-7765
4 years ago
Steve Riesenberg
3af619d565
Add hasIpAddress to Reactive Kotlin DSL
...
Closes gh-10571
4 years ago
Steve Riesenberg
bb2d80fea3
Update copyright year
...
Issue gh-10557
4 years ago
Steve Riesenberg
f49c286050
Fix case sensitive headers comparison
...
Closes gh-10557
4 years ago
Arnaud Mergey
dbe4d704f8
Add SP NameIDFormat Support
...
closes gh-9115
4 years ago
Josh Cummings
a68411566e
Polish Memory Leak Mitigation
...
Issue gh-9841
4 years ago
Hiroshi Shirosaki
2bc643d6c8
Address SecurityContextHolder memory leak
...
To get current context without creating a new context.
Creating a new context may cause ThreadLocal leak.
Closes gh-9841
4 years ago
Josh Cummings
1251cde04c
Add Missing Since
...
Issue gh-10482
4 years ago
Igor Pelesic
a3a9de1b9b
PermitAllSupport supports AuthorizeHttpRequestsConfigurer
...
PermitAllSupport supports either an ExpressionUrlAuthorizationConfigurer or an AuthorizeHttpRequestsConfigurer. If none or both are configured an error message is thrown.
Closes gh-10482
4 years ago
Steve Riesenberg
f838b7cb1d
Polish gh-10081
4 years ago
Jonas Dittrich
23e895f0b1
Add ObjectIdentityGenerator customization to JdbcAclService
...
Providing the possibility to change, how ObjectIdentitys are created inside the BasicLookupStrategy,JdbcAclService
There was a problem with hard coded object identity creation inside the BasicLookupStrategy and the JdbcAclService. It was overkill to overwrite
these classes only for changing this, so introducing an ObjectIdentityGenerator seems the be the better solution here. At default, the standard
ObjectIdentityRetrievalStrategyImpl is used, but can be customized due to setters.
Closes gh-10079
4 years ago
Steve Riesenberg
204f0b4599
Polish gh-10007
4 years ago
Guirong Hu
43317c5a61
Support IP whitelist for Spring Security Webflux
...
Closes gh-7765
4 years ago
Jonas Erbe
dec858a5b7
Fix JwtClaimValidator wrong error code
...
Previously JwtClaimValidator returned the invalid_request error on claim validation failure.
But validators have to return invalid_token errors on failure according to:
https://datatracker.ietf.org/doc/html/rfc6750#section-3.1 .
Also see gh-10337
Closes gh-10337
4 years ago
Eleftheria Stein
bbeca7cd65
Polish LDAP serialization
...
Closes gh-9263
4 years ago
Markus Heiden
3c18278123
Start with LDAP Jackson2 mixins
...
Issue gh-9263
4 years ago
Henning Poettker
bb99d7d95a
Fix return type for NoOpPasswordEncoder bean in documentation
4 years ago
Lars Grefer
d736a2b358
Remove usages of Gradle's jcenter() repository
...
Closes gh-10253
4 years ago
Lars Grefer
cf95d3f91e
Fix Gradle Deprecation Warnings
4 years ago
Dávid Kováč
17e28fa7aa
Update clockSkew javadoc according to implementation
...
Closes gh-10174
4 years ago
Josh Cummings
739cdc1a4c
Polish AuthRequestConverter Sample Doc
...
Issue gh-10364
4 years ago
Norbert Nowak
02cd1dd3c4
Fix AuthnRequestConverter Sample Typos
...
Closes gh-10364
4 years ago