724 Commits (bc4ad52febfc5fe8b419d64aab6e40f1256f5dc6)

Author SHA1 Message Date
Josh Cummings 4ddec07d0e
Add default AuthorizationManager 4 years ago
Steve Riesenberg dce1c30522
Add support for BREACH 4 years ago
Steve Riesenberg 475b3bb6bb
Add deferred CsrfTokenRepository.loadDeferredToken 4 years ago
Marcus Da Coregio 039e0328e1 Simplify Java Configuration RequestMatcher Usage 4 years ago
Daniel Garnier-Moiroux 93250013e4
Make X-Xss-Protection configurable through ServerHttpSecurity 4 years ago
Steve Riesenberg 46696a9226
CsrfTokenRequestHandler extends CsrfTokenRequestResolver 4 years ago
Steve Riesenberg 5d757919a2
Add SecurityContextHolderStrategy to new repository 4 years ago
Rob Winch d94677f87e CsrfTokenRequestAttributeHandler -> CsrfTokenRequestHandler 4 years ago
Steve Riesenberg 86fbb8db07 Add new interfaces for CSRF request processing 4 years ago
Bert Vanwolleghem a5351f3d89
LogoutPageGeneratingWebFilter Uses Context Path 4 years ago
Rob Winch 2fb625db84 Remove mockito deprecations 4 years ago
Rob Winch 5b64526ba9 Add CsrfFilter.csrfRequestAttributeName 4 years ago
Rob Winch 666f175225 LazyCsrfTokenRepository#loadToken Supports Deferring Delegation 4 years ago
Marcus Da Coregio ead587c597 Consistently handle RequestRejectedException if it is wrapped 4 years ago
Marcus Da Coregio 6a2ca52aae Consistently handle RequestRejectedException if it is wrapped 4 years ago
Marcus Da Coregio 1c4d6ed098 Consistently handle RequestRejectedException if it is wrapped 4 years ago
Rob Winch 269c711a64 RequestAttributeSecurityContextRepository never null SecurityContext 4 years ago
Rob Winch c9f8d2b111 RequestAttributeSecurityContextRepository never null SecurityContext 4 years ago
Marcus Da Coregio f45c4d4b8e Add SHA256 as an algorithm option for Remember Me token hashing 4 years ago
Rob Winch 415a674edc AnonymousAuthenticationFilter Avoids Eager SecurityContext Access 4 years ago
Rob Winch 28c0d1459c Request Cache supports matchingRequestParameterName 4 years ago
Josh Cummings 03a5c3b08a
Use SecurityContextHolderStrategy for Concurrency Filter 4 years ago
Josh Cummings 135e602472
Use SecurityContextHolderStrategy for Digest 4 years ago
Josh Cummings e1c211c11f
Use SecurityContextHolderStrategy for Switch User 4 years ago
Josh Cummings ee66850aed
Add SecurityContextHolderStrategy for Jaas 4 years ago
Josh Cummings 0fee05d023
Use SecurityContextHolderStrategy for AuthenticationFilter 4 years ago
Alonso Araya Calvo 1ac1271972 Adds the ability to set the CSRF Token cookie max age value 4 years ago
Rob Winch d32f74d19d SecurityContextHolder Deferred SecurityContext 4 years ago
Rob Winch 29db051f7a Cache SecurityContextRepository.loadContext(HttpServletRequest) Result 4 years ago
Rob Winch 591d1edc7d Cache SecurityContextRepository.loadContext(HttpServletRequest) Result 4 years ago
Josh Cummings 31e25b115e Add SecurityContextHolderStrategy to Default Components 4 years ago
j3graham 29ba67b6d7 Remove dependency on commons-codec by using java.util.Base64 4 years ago
Zhivko Delchev e97c5a533b Reverse content type check 4 years ago
Zhivko Delchev d882bfcf2b Reverse content type check 4 years ago
Zhivko Delchev cf69cdf008 Reverse content type check 4 years ago
Evgeniy Cheban 362f15534e createEvaluationContext should defer lookup of Authentication 4 years ago
Rob Winch 7d97839235 StrictHttpFirewall allows CJKV characters 4 years ago
Rob Winch 077c9e0b3e StrictHttpFirewall allows CJKV characters 4 years ago
Rob Winch e2eed33eca Add StrictHttpFirewall.allow* new lines and separators 4 years ago
Rob Winch e0a6a9efa9 StrictHttpFirewall allows CJKV characters 4 years ago
Rob Winch 538252cf07 AntRegexRequestMatcher Optimization 4 years ago
Rob Winch 04ca7ef91b Extract rejectNonPrintableAsciiCharactersInFieldName 4 years ago
Rob Winch 70863952ae AntRegexRequestMatcher Optimization 4 years ago
Rob Winch af95be34c6 Extract rejectNonPrintableAsciiCharactersInFieldName 4 years ago
Rob Winch ee28896f42 AntRegexRequestMatcher Optimization 4 years ago
Rob Winch 6b823fb27e Extract rejectNonPrintableAsciiCharactersInFieldName 4 years ago
Josh Cummings ffaf5b4e61
Polish WebExpressionAuthorizationManager 4 years ago
Evgeniy Cheban 07b0be3f42 Add AuthorizationManager that uses ExpressionHandler 4 years ago
Marcus Da Coregio ce86f4e4b5 Polish ServerWebExchangeDelegatingServerHttpHeadersWriter 4 years ago
David Herberth 57cededd49 Add DelegatingServerHttpHeadersWriter 4 years ago