Marcus Da Coregio
bb0c336ae8
Deprecate Saml2AuthenticationRequestFactory
...
Closes gh-11080
4 years ago
Josh Cummings
b39f213e64
Revert "Add AuthorizationManager to Messaging"
...
This reverts commit 77a6e014a9 .
4 years ago
Josh Cummings
77a6e014a9
Add AuthorizationManager to Messaging
...
Closes gh-11076
4 years ago
Pascal Verdage
b71d9bfdc2
Fix typo
4 years ago
Josh Cummings
057f4a86d5
Add default strategy constructor
...
Closes gh-11059
4 years ago
Josh Cummings
0be2a03741
Polish SecurityContextChannelInterceptorTests
...
Issue gh-10973
4 years ago
Josh Cummings
66213e5b2e
Add Default Test to HttpBasicConfigurerTests
...
Issue gh-10973
4 years ago
Josh Cummings
47c8676be7
Polish Saml2LoginConfigurerTests
...
Issue gh-10973
4 years ago
Jihoon Cha
af7f943325
Prevent instantiation of DelegatingPasswordEncoder if idPrefix contains idSuffix
...
Closes gh-10933
4 years ago
Eleftheria Stein
725a57fccc
Remove blocking call from ExceptionTranslationWebFilter
...
This also means that the exception message is no longer retrieved from a MessageSource. This is consistent with the other WebFilters.
Closes gh-10864
4 years ago
Simone Giannino
ea373645e5
Update saganCreateRelease property referenceDocUrl
...
- Updated saganCreateRelease task with the new referenceDocUrl for reference documentation
Closes gh-11016
4 years ago
Johannes Graf
d4931ecf2b
use okta as registration id
...
looks like `ping` is some registration id used in the past.
4 years ago
Josh Cummings
c175118f62
Use RequestMatcherEntry
...
Closes gh-11046
4 years ago
Josh Cummings
04c483387e
Document Authorization Events
...
Issue gh-9288
4 years ago
Josh Cummings
061f69eb70
Polish Authorization Event Support
...
- Added spring-security-config support
- Renamed classes
- Changed contracts to include the authenticated user and secured
object
- Added method security support
Issue gh-9288
4 years ago
Parikshit Dutta
bd9434882f
Add authorization events
...
Closes gh-9288
4 years ago
Josh Cummings
a43677d36a
Simplify PrePostMethodSecurityConfiguration
...
Issue gh-9288
4 years ago
Marcus Da Coregio
c73bd4756d
Change samplesBranch property to point to correct branch
...
Closes gh-11040
4 years ago
Marcus Da Coregio
6c52c52a68
Use ServletContext in AuthorizationManagerWebInvocationPrivilegeEvaluator
...
Closes gh-10908
4 years ago
Rob Winch
67fd46bfa6
Add SecurityContextRepository.loadContext(HttpServletRequest)
...
This allows loading the SecurityContext lazily, without the need for the
response, and does not attempt to automatically save the request when
the response is comitted.
Closes gh-11028
4 years ago
Rob Winch
8940719dbb
HttpSessionSecurityContextRepository support null HttpServletResponse
...
Closes gh-11029
4 years ago
Eleftheria Stein
d4d6ddbaae
Fix formatting in reference docs
4 years ago
Yuriy Savchenko
446ab5047c
Add authorizeHttpRequests to Kotlin DSL
...
Closes gh-10481
4 years ago
Yuriy Savchenko
3016ed0067
Fix typos in Kotlin DSL docs
...
Issue gh-10481
4 years ago
Marcus Da Coregio
7deaab8822
Next development version
4 years ago
Marcus Da Coregio
ed0a323a71
Release 5.7.0-M3
4 years ago
Marcus Da Coregio
94adc640ca
Update spring-data-bom to 2021.2.0-M4
...
Closes gh-11014
4 years ago
Marcus Da Coregio
0c9e73876d
Update org.springframework to 5.3.17
...
Closes gh-11011
4 years ago
Marcus Da Coregio
e128e8d87e
Update htmlunit-driver to 2.60.0
...
Closes gh-11010
4 years ago
Marcus Da Coregio
fe5cfa9cae
Update org.jetbrains.kotlin to 1.6.20-RC
...
Closes gh-11009
4 years ago
Marcus Da Coregio
01c2694073
Update hibernate-entitymanager to 5.6.7.Final
...
Closes gh-11008
4 years ago
Marcus Da Coregio
393f182b40
Update htmlunit to 2.60.0
...
Closes gh-11007
4 years ago
Marcus Da Coregio
dae500fb9b
Update io.projectreactor to 2020.0.17
...
Closes gh-11005
4 years ago
Marcus Da Coregio
44aee2034b
Update mockk to 1.12.3
...
Closes gh-11004
4 years ago
Marcus Da Coregio
106d77a1b9
Update com.nimbusds to 9.31
...
Closes gh-11003
4 years ago
Marcus Da Coregio
661848ef7e
Update jackson-bom to 2.13.2
...
Closes gh-11000
4 years ago
Marcus Da Coregio
84717e0546
Update logback-classic to 1.2.11
...
Closes gh-10999
4 years ago
Steve Riesenberg
28dd7dabfb
Update What's New for 5.7
4 years ago
Steve Riesenberg
987ee2e67a
Polish gh-10911
4 years ago
David Kirstein
1b29c43a11
Use configurable charset in ServerHttpBasicAuthenticationConverter
...
Closes gh-10903
4 years ago
Steve Riesenberg
c38c722473
Update What's New for 5.7
4 years ago
Steve Riesenberg
f0168c6c27
Add support for customizing claims in JWT Client Assertion
...
Closes gh-9855
4 years ago
Joe Grandja
4a8219d16c
Update whats-new.adoc with gh-9812
4 years ago
Joe Grandja
50d315d833
Remove unused code
4 years ago
Joe Grandja
a2ffc88294
Allow configuring PKCE for confidential clients
...
Closes gh-6548
4 years ago
ShinDongHun1
7955e5ac52
Polish UsernamePasswordAuthenticationFilter method
...
Closes gh-10970
4 years ago
Josh Cummings
cf29bf996c
Polish InResponseTo support
...
- Moved methods so methods are listed before the methods they call
- Adjusted exception handling so no exceptions are eaten
- Adjusted so that malformed_request_data is returned with request data is malformed
- Refactored methods to have only immutable method parameters
- Removed usage of Stream API
- Moved AuthnRequestUnmarshaller into static block so that only looked
up once
Issue gh-9174
4 years ago
Elias Lousseief
3c878549b5
Add support for validation of InResponseTo
...
Whenever an InResponseTo is present in the SAML2 response and / or any of its assertions, it will be validated against the stored SAML2 request. If the request is missing or the ID of the request does not match the InResponseTo, validation fails. If there is no InResponseTo, no validation of it is done (as opposed to checking whether there is a saved request or not and then failing based on that).
Closes gh-9174
4 years ago
Elias Lousseief
836f203d44
Refactored OpenSaml4AuthenticationProviderTests
...
Factored out repeatedly used code for signing a request.
4 years ago
Simone Giannino
73003d59d6
OAuth 2.0 logout handler resolves uri placeholders
...
- OidcClientInitiatedLogoutSuccessHandler can automatically resolve placeholders like baseUrl and registrationId inside the postLogoutRedirectUri
Issue gh-7900
4 years ago