Steve Riesenberg
b3e0f167ff
Fix case sensitive headers comparison
...
Closes gh-10557
4 years ago
Steve Riesenberg
41c6776455
Fix case sensitive headers comparison
...
Closes gh-10557
4 years ago
Josh Cummings
1251cde04c
Add Missing Since
...
Issue gh-10482
4 years ago
Igor Pelesic
a3a9de1b9b
PermitAllSupport supports AuthorizeHttpRequestsConfigurer
...
PermitAllSupport supports either an ExpressionUrlAuthorizationConfigurer or an AuthorizeHttpRequestsConfigurer. If none or both are configured an error message is thrown.
Closes gh-10482
4 years ago
Josh Cummings
7e55c84cfc
Add Missing Since
...
Issue gh-10482
4 years ago
Igor Pelesic
72109e2921
PermitAllSupport supports AuthorizeHttpRequestsConfigurer
...
PermitAllSupport supports either an ExpressionUrlAuthorizationConfigurer or an AuthorizeHttpRequestsConfigurer. If none or both are configured an error message is thrown.
Closes gh-10482
4 years ago
Steve Riesenberg
204f0b4599
Polish gh-10007
4 years ago
Guirong Hu
43317c5a61
Support IP whitelist for Spring Security Webflux
...
Closes gh-7765
4 years ago
Steve Riesenberg
898ba67098
Polish gh-10007
4 years ago
Guirong Hu
9f51240bf1
Support IP whitelist for Spring Security Webflux
...
Closes gh-7765
4 years ago
Steve Riesenberg
9a9136d96d
Fix import spacing
4 years ago
Steve Riesenberg
c6a27d44e5
Remove failing test due to HttpMethod changes
...
Closes gh-10569
4 years ago
Marcus Da Coregio
25feedb870
Fix removal of framework deprecated code
...
Issue https://github.com/spring-projects/spring-framework/issues/27686
4 years ago
Marcus Da Coregio
01be7eca6e
Improve log message when no CSRF token found
...
Closes gh-10436
4 years ago
Marcus Da Coregio
5a47e17a0d
Improve log message when no CSRF token found
...
Closes gh-10436
4 years ago
Marcus Da Coregio
e05c9f4bba
Improve log message when no CSRF token found
...
Closes gh-10436
4 years ago
Marcus Da Coregio
2bf7a5ae80
Improve log message when no CSRF token found
...
Closes gh-10436
4 years ago
Rob Winch
bd34d70f97
Prevent Save @Transient Authentication with existing HttpSession
...
Previously, @Transient Authentication would get saved if an existing
HttpSession existed but it shouldn't.
This commit always prevents @Transient Authentication from being saved.
Closes gh-9992
4 years ago
Rob Winch
96a6fef820
Prevent Save @Transient Authentication with existing HttpSession
...
Previously, @Transient Authentication would get saved if an existing
HttpSession existed but it shouldn't.
This commit always prevents @Transient Authentication from being saved.
Closes gh-9992
4 years ago
Marcus Da Coregio
db60df2f9c
Update to Spring Framework 6.0
...
Issue gh-10360
4 years ago
Marcus Da Coregio
caad3d57e2
Improve log message when no CSRF token found
...
Closes gh-10436
4 years ago
Marcus Da Coregio
89db1c37a3
Update DefaultWebInvocationPrivilegeEvaluator to use current ServletContext
...
Closes gh-10208
4 years ago
Marcus Da Coregio
00f4033b9b
Update DefaultWebInvocationPrivilegeEvaluator to use current ServletContext
...
Closes gh-10208
4 years ago
Rob Winch
e4a76b0ec9
Checkstyle Fixes
...
- Javadoc tag ordering
- Private constructors before inner classes
Issue gh-10394
4 years ago
Emil Sierżęga
04b47c5928
Fixed various broken links in Javadocs
4 years ago
Emil Sierżęga
a188138715
Javadocs author tag doesn't work in methods
4 years ago
Rob Winch
f836897190
Checkstyle Fixes
...
- Javadoc tag ordering
- Private constructors before inner classes
Issue gh-10394
4 years ago
Rob Winch
e1f4ec1137
Fix Jackson
4 years ago
Josh Cummings
ba468c7e6e
Restructure SwitchUserFilter Logs
...
Issue gh-6311
4 years ago
Josh Cummings
6e86fab19d
Restructure SwitchUserFilter Logs
...
Issue gh-6311
4 years ago
Josh Cummings
21f0ccd088
Restructure SwitchUserFilter Logs
...
Issue gh-6311
4 years ago
Josh Cummings
9481122e02
Restructure SwitchUserFilter Logs
...
Issue gh-6311
4 years ago
Marcus Da Coregio
faec20bc69
Update DefaultWebInvocationPrivilegeEvaluator to use current ServletContext
...
Closes gh-10208
4 years ago
Josh Cummings
7b98c2ea95
Restructure SwitchUserFilter Logs
...
Issue gh-6311
4 years ago
Eleftheria Stein
7d81a52780
Allow AuthenticationPrincipal argument type to be primitive
...
Closes gh-10172
4 years ago
heowc
84d173c310
Fix typo
4 years ago
Bogdan Ilchyshyn
a4c088a3b3
Introducing WebSessionServerLogoutHandler
...
Closes gh-4838
5 years ago
Hiroshi Shirosaki
6f3e346b76
Add SecurityContextHolder#addListener
...
Closes gh-10032
5 years ago
Josh Cummings
b8d51725c7
Immutable SecurityContext
...
Issue gh-10032
5 years ago
Rob Winch
b6ff4d3674
Fix mockito UnnecessaryStubbingException
5 years ago
Rob Winch
3e93b024d6
openrewrite Junit Migration
5 years ago
Rob Winch
14240b2559
Remove Powermock
...
Powermock does not support JUnit5 yet, so we need to remove it
to support JUnit 5. Additionally, maintaining additional libraries
adds extra work for the team.
Mockito now supports final classes and static method mocking. This
commit replaces Powermock with mockito-inline.
Closes gh-6025
5 years ago
Evgeniy Cheban
d121ab9565
Support A Well-Known URL for Changing Passwords
...
Closes gh-8657
5 years ago
Alexey Markevich
3219fd554d
DigestAuthenticationFilter decodes nonce only once
...
Closes gh-8455
5 years ago
Steve Riesenberg
3bb8e1d200
Remove redundant translations in spring-security-web
5 years ago
Ruben Suarez Alvarez
7cd344acab
Add spanish translation of insufficient authentication and cookie stolen
5 years ago
Josh Cummings
ca76c54471
Polish CsrfWebFilterTests
...
Issue gh-9113
5 years ago
Tomoki Tsubaki
0c8b6df82a
Cache Mono that generate the CSRF token
...
Closes gh-9113
5 years ago
AlexeyAnufriev
baac9e0cf2
Properly clean cookies with context path after logout
...
Closes gh-8846
5 years ago
Marcus Hert da Coregio
02285708eb
Adjust createNewSessionIfAllowed to prevent NPE
...
Ensure that isTransientAuthentication reuses the same authentication object from saveContext
Closes gh-8947
5 years ago