Ben Alex
a5ffda7369
SEC-63: Do not return an absolute URL unless switching from HTTP to HTTPS.
21 years ago
Ben Alex
c6d5363e5d
SEC-60: Make method more friendly towards Hibernate detached object. Please note my comments in the JIRA task, as I believing calling toString() is not an unreasonable expectation.
21 years ago
Ben Alex
d49198a944
SEC-43: Eliminate id column.
21 years ago
Ben Alex
41202112bc
SEC-37: Only update HttpSession if SecurityContext has actually been changed.
21 years ago
Ben Alex
494e35f009
Jalopy styling.
21 years ago
Luke Taylor
24a78be159
Corrected link in Javadoc.
21 years ago
Luke Taylor
c065c46668
Javadoc correction: ContextHolder -> SecurityContextHolder
21 years ago
Luke Taylor
df4b8f602f
Javadoc correction: SecureContext -> SecurityContext
21 years ago
Carlos Sanchez
b2363dfe07
SEC-62 Add maven 2 support
21 years ago
Ray Krueger
a39339674e
login.config.url should be set to a url, not a file path
...
The System property java.security.auth.login.config will only be used if the useSystemProperty option is enabled. This is the default.
21 years ago
Scott McCrory
bc14dd62db
Fixed CVS line break
21 years ago
Scott McCrory
4717b64b83
Updated Siteminder auth processing filter and added test case. As of this weekend, this version is in production at a large financial org.
21 years ago
Ben Alex
0f5e9ad372
Fix NPE. Thanks to Tom Dunstan.
21 years ago
Ben Alex
f5741962ed
Add createSessionAllowed property, which should be set to false to avoid unnecessary session creation.
21 years ago
Marc-Antoine Garrigue
60d3b6505b
Finalizing the validation, entry point and channel processor concerning captchas. Replacing the Thread.sleep() in captchaChannelProcessorTest to avoid the build break issue.
21 years ago
Mark St. Godard
fb3f4af3b2
when extracting the original user, fix by referencing by the interface (UserDetail) rather than the concrete class (User)
21 years ago
Mark St. Godard
24394b7b2b
added fix to preserve custom UserDetails implementations (Matt DeHoust fix recommendation)
21 years ago
Ben Alex
d44b570087
Disable failing tests until Marc-Antoine has a chance to look at them.
21 years ago
Ben Alex
ae9e7733db
Fix broken tests.
21 years ago
Ben Alex
35ca25f085
BasicAuthenticationProcessingFilter no longer creates HttpSession via WebAuthenticationDetails call.
21 years ago
Ben Alex
c7dcceb05c
Do not setAuthenticated(false) in the event of a public (unsecured) invocation. Thanks to Joseph Dane for reporting this issue on acegisecurity-developer on 3 September 2005.
21 years ago
Mark St. Godard
486bbee35d
added context path to redirect
21 years ago
Mark St. Godard
9d359780d9
finish user context switch event publishing
21 years ago
Mark St. Godard
20ebb668a6
Added event for user context switching and updated switch user filter
21 years ago
Ben Alex
55f5c3397a
Relocated JdbcDaoExtendedImpl.convertAclObjectIdentityToString to superclass (pursuant to suggestion made by Tim Kettering on acegisecurity-developer).
21 years ago
Ray Krueger
2bda6ec25c
Fix: SEC-48 http://opensource2.atlassian.com/projects/spring/browse/SEC-48
...
If the principal is an instanceof UserDetails, UserDetails.getUsername();
21 years ago
Ben Alex
40a81ed220
Revisit synchonization issue and correct problem identified by Volker Malzahn.
21 years ago
Mark St. Godard
ec5e39c2e8
Initial checkin of user security context switching (see SEC-15). This is the first cut of the SwitchUserProcessingFilter that handles switching to a target uesr and exiting back to the original user. Note: This is going to be used for the common use-case of an Administrator 'switching' to another user (i.e. ROLE_ADMIN -> ROLE_USER). This is the initial cut of a Unix 'su' for Acegi managed web applications.
21 years ago
Luke Taylor
725ec767b6
Javadoc typo corrected (as suggested on mailing list)
21 years ago
Scott McCrory
c2c48b905b
Added package.html files to reamining java packages (see http://opensource.atlassian.com/projects/spring/browse/SEC-41 )
21 years ago
Scott McCrory
f5975dcf30
Whoops, almost forgot to remove System.out debug lines :-/
21 years ago
Scott McCrory
891cd7380c
Mirrored Ben's FilterChainProxy.java 1.5 spelling fix to its corresponding test class, which depended on equality of the exception message. All JUnit tests pass now.
21 years ago
Scott McCrory
dc31553f2a
Syntax
21 years ago
Scott McCrory
db4ed4bc44
Added debug statement to AbstractTicketValidator to help with Acegi+CAS+SSL setup (thanks Seth Ladd for the patch) (see http://opensource.atlassian.com/projects/spring/browse/SEC-34 )
21 years ago
Scott McCrory
c66c5dfab5
AuthorizeTag no longer depends on JDK 1.4. Tested on Websphere 5.0 w/JDK 1.3 (see http://opensource.atlassian.com/projects/spring/browse/SEC-11 )
21 years ago
Scott McCrory
32f62d1ef1
Added SiteminderAuthenticationProcessingFilter for Ben's review. <Untested>.
21 years ago
Ben Alex
f625d06cd9
Avoid expense of HttpSession when working with anonymous users.
21 years ago
Ben Alex
4ad98a7df3
Spelling correction, thanks to Zack Chandler.
21 years ago
Ben Alex
c5ba30b001
Comment how to make a signing certificate.
21 years ago
Ray Krueger
4b98d357ff
SecureContextLoginModuleTest has been renamed to ...Tests as per Acegi project.
...
SecureContextLoginModule now throws a LoginException if there is no authentication present, if the ignoreMissingAuthentication option is true, the login() method will simply return false.
21 years ago
Luke Taylor
e51c38aec9
Removed reference in Javadoc to obtaining and validating the SecureContext (checking for null etc), as this is no longer relevant.
21 years ago
Luke Taylor
c89d4a8add
Added trimming of whitespace to tokens and use of Springs StringUtils.hasText() to check for content in the string passed to setAsText.
21 years ago
Marc-Antoine Garrigue
3287439421
Initial commit for captcha adapter
21 years ago
Luke Taylor
74588c8e53
Move acegifier code from core.
21 years ago
Luke Taylor
5bbc54ac42
Javadoc typo corrected
21 years ago
Ben Alex
d9b1a8e83c
Fix typo in InteractiveAuthenticationSucces(s)Event
21 years ago
Ben Alex
c7bfeeaf58
Clarify local variable name given it was the same as a member variable.
21 years ago
Luke Taylor
ab065923d4
Correct doctype for generated web.xml files and add declaration to test file.
21 years ago
Luke Taylor
22a28f3b39
Separate InMemoryResource class for use in Acegifier web application.
21 years ago
Luke Taylor
7268c81192
Fix for SEC-27. Now checks for a null authentication before proceeding to fire the success event.
21 years ago