1955 Commits (c2bc6fafe21167abb3340e9fdea633324b7141d6)

Author SHA1 Message Date
Luke Taylor 0da99171da SEC-1250: RequestHeaderPreAuthenticatedProcessingFilter cannot be use to fail back to another authentication type. Added exceptionIfHeaderMissing property. 16 years ago
Luke Taylor 3f72983a1e SEC-1257: Some additional API changes to use Collection instead of List... 16 years ago
Luke Taylor 1286741c7c SEC-1259: Improve consistency of authentication filter names. 16 years ago
Luke Taylor f213cc5d9e SEC-1257: APIs using List<ConfigAttribute> should use a Collection instead. Converted. 16 years ago
Luke Taylor caff3ee9ba SEC-1231: Authentication.getAuthorities should be of type Collection<GrantedAuthority> and not List<GrantedAuthority>. Refactored the interface and related classes to match (UserDetails etc). 16 years ago
Luke Taylor 07d7c0ddae Renamed form and openID filters to shorten names 16 years ago
Luke Taylor 1042305cfe Renamed web.wrapper to web.servletapi. Added some package.html files. 16 years ago
Luke Taylor 673cf300fb SEC-1229: Refactoring to remove package cycles. 16 years ago
Luke Taylor acf13c74ca SEC-1229: Refactored authentication.concurrent in core, moving classes into core.session 16 years ago
Luke Taylor 2b89ebdfbb SEC-1229: Further doc and mods to namespace config/naming to make it more consistent 16 years ago
Luke Taylor 073198886d SEC-1255: Modified UrlUtils. Full request URL for redirects uses the requestURI (which is encoded). The URL for path comparsions is built using the servletpath, as before. 16 years ago
Luke Taylor abba569282 Tidying. 16 years ago
Luke Taylor 1ead8472d1 SEC-1229: Added failure handler to the SessionManagementFilter to deal with concurrent login errors. 16 years ago
Luke Taylor bf39a5bb36 Added extra logging. 16 years ago
Luke Taylor 731402e9f5 SEC-525: [PATCH] Add AccessCheckerTag based on URL resource access permissions. Added functionality to "authorize" tag to allow evaluation of whether a particual url is accessible to the user. Uses a WebInvocationPrivilegeEvaluator registered in the application context. 17 years ago
Luke Taylor 1c4a809e09 SEC-1245: Add role hierarchy support to expression handlers. Done. 17 years ago
Luke Taylor e7486fc203 Removed Ordered interface from Http403EntryPoint (unused). 17 years ago
Luke Taylor 40cf50fc98 SEC-1148: Javadoc. 17 years ago
Luke Taylor ff78ec00f7 SEC-1226: Additional Javadoc. 17 years ago
Luke Taylor 23c8f479b8 SEC-1226: Renamed useRelativeContext to contextRelative to match corresponding flag name in Spring Framework. 17 years ago
Luke Taylor 593d2e227a SEC-1226: Renamed useRelativeContext to contextRelative to match corresponding flag name in Spring Framework. 17 years ago
Luke Taylor 9c7423599e SEC-1167: Extended SavedRequest interface to allow it to be used by wrapper. Removed null checks in wrapper, as the SavedRequest cannot now be null. 17 years ago
Luke Taylor 4064b7b4f6 SEC-1167: Introduce more flexible SavedRequest handling. Introduced interface for SavedRequest. 17 years ago
Luke Taylor acd10dd716 SEC-1243: Make determineTargetUrl protected. 17 years ago
Luke Taylor ac4e7bbadb SEC-1241: Make sure saved request is removed after a match. 17 years ago
Luke Taylor f518da9d8b SEC-1236: Using HTTP Method-specific intercept-urls causes patterns with no method to be ignored. Fixed by also checking null key in map if no method-specific attributes are found. 17 years ago
Luke Taylor 5bdfd8cd77 Tidying imports etc to remove compiler warnings. 17 years ago
Luke Taylor 002b788a8c Minor refactoring. 17 years ago
Mike Wiesner 5623c13038 SEC-1047: Added an option to DigestProcessingFilter that the created Authentication object is now marked as "authenticated" 17 years ago
Luke Taylor 936326f4ab SEC-1180: Unreachable code inside UrlUtils.buildRequestUrl(...). Removed code block. 17 years ago
Luke Taylor 32dbb7e8bd import cleaning 17 years ago
Luke Taylor 2039200617 SEC-1217: AbstractRememberMeServices should set 'secure' attribute on remember-me cookie if in secure context. Added "useSecureCookie" configuration property and corresponding use-secure-cookie attribute in namespace. 17 years ago
Luke Taylor b2c2b93545 SEC-1190: Added "invalidateSessionOnPrincipalChange" property to AbstactPreAuthenticatedProcessingFilter. If set to true (the default) and a new principal is detected, the existing session will be invalidated before proceeding to authenticate the user. 17 years ago
Luke Taylor 3cc47c9c4d SEC-1190: Added "checkForPrincipalChanges" property to AbstactPreAuthenticatedProcessingFilter. 17 years ago
Luke Taylor dbcb13ad14 SEC-1229: Redesign Concurrent Session Control implementation. Renamed session strategy interface and introduced SessionAuthenticationException for rejection of session/Authentication combination. 17 years ago
Luke Taylor a4ccc4ac21 Make WebSecurityExpressionRoot public to allow reuse. 17 years ago
Luke Taylor 471206a29d SEC-1229: Redesign Concurrent Session Control implementation. Added ConcurrentSessionControlAuthenticatedSessionStrategy 17 years ago
Luke Taylor ab0d66071a SEC-1226: Introduce RedirectStrategy to replace RedirectUtils. Implemented strategy and applied throughout relevant classes. 17 years ago
Luke Taylor fe33f08b73 SEC-1201: Allow requires-channel attribute to take placeholders. 17 years ago
Luke Taylor 0b5160d155 Javadoc correction. 17 years ago
Luke Taylor e6631be778 Import cleaning 17 years ago
Luke Taylor 6f76fe6fbb Import cleaning 17 years ago
Luke Taylor eb059cfd12 SEC-1211: removed SessionUtils (no longer used) 17 years ago
Luke Taylor f536c80020 SEC-1202: Removed SpringSecurityFilter and replaced with use of GenericFilterBean from spring-web 17 years ago
Luke Taylor c12e5b4d0b SEC-1142: Renamed setter argument to match property. 17 years ago
Luke Taylor ea73fd0130 SEC-1142: Simplified implementation by removing template method. 17 years ago
Luke Taylor 90d76373cc SEC-1142: Support for session timeout detection. Added redirect to invalidSessionUrl in SessionManagementFilter when an invalid session Id is supplied in the request. 17 years ago
Luke Taylor 3e6054b69f SEC-1211: Rename SessionFixationProtectionFilter to SessionManagementFilter, since it no longer performs session-fixation protection directly, but just executes the AuthenticatedSessionStrategy. 17 years ago
Luke Taylor 5e285b3692 SEC-1211: Set the default AuthenticatedSessionStrategy to a null implementation to preserve existing behaviour. 17 years ago
Luke Taylor 609a68b12a SEC-1077: Added DefaultAuthenticatedSessionStrategy test to check that saved request attribute is retained when migrateAttributes is false. 17 years ago