Marcus Da Coregio
7e9d707c7d
Allow customize the AuthenticationConverter in BasicAuthenticationFilter
...
Closes gh-13988
2 years ago
Seongguk Jeong
d8eadd2207
Replace deprecated method
...
Replace HttpMethod.resolve() to HttpMethod.valueOf()
2 years ago
Marcus Da Coregio
64e2a2ff8b
Apply updated Code Style
...
Closes gh-13881
2 years ago
Steve Riesenberg
ff374935fb
Verify ReactorContext when using Virtual Threads
...
Closes gh-12791
2 years ago
Steve Riesenberg
ecf8467cac
Fix tests on JDK 21
...
Issue gh-12790
Issue gh-13811
2 years ago
Steve Riesenberg
d48b8697bd
Fix mockito usage
...
Issue gh-13810
2 years ago
Marcus Da Coregio
18e88366d2
Resolve The matchingRequestParameterName From The Query String
...
Prior to this commit, the ServletRequest#getParameter method was used in order to verify if the matchingRequestParameterName was present in the request. That method has some side effects like interfering in the execution of the ServletRequest#getInputStream and ServletRequest#getReader method when the request is an HTTP POST (if those methods are invoked after getParameter, or vice-versa, the content won't be available). This commit makes that we only use the query string to check for the parameter, avoiding draining the request's input stream.
Closes gh-13731
2 years ago
Josh Cummings
2a1cf98b80
Update Copyright and Formatting
...
Issue gh-13615
2 years ago
Bjorn Harvold
5e715c5297
Improve StrictHttpFirewall Error Messaging
...
Better error strings for invalid header and parameter values.
Closes gh-13615
2 years ago
Tim te Beek
9df9cb5aed
refactor: AssertJ best practices
...
Use this link to re-run the recipe: https://app.moderne.io/recipes/builder/bGVuS?organizationId=RGVmYXVsdA%3D%3D
Co-authored-by: Moderne <team@moderne.io>
2 years ago
Marcus Da Coregio
ce012a4661
CookieRequestCache Should Preserve Request Locale
...
Closes gh-13792
2 years ago
Marcus Da Coregio
96d1763fc4
WWW-Authenticate header should not be added twice
...
Closes gh-13737
2 years ago
Josh Cummings
a4d8c62ad7
withHttpOnlyCookie defaults to false
...
Closes gh-13659
2 years ago
Steve Riesenberg
985e569685
Polish gh-13608
2 years ago
Olivier Vanekem
6353d90047
Add integrity attribute for signin.css
...
Closes gh-13486
2 years ago
Josh Cummings
82c0ddc56d
Polish
...
- Add Reactive equivalent
- Update copyright
Issue gh-13310
2 years ago
Kevin2Jordan
e21da061d3
Suppress ArrayIndexOutOfBoundsException in XorCsrfTokenRequestAttributeHandler
...
Closes gh-13310
2 years ago
Seongguk Jeong
bcd4dcc15c
Refactor equals method
...
Using the accessor method for fields instead of directly access
2 years ago
Seongguk Jeong
ea19f82b8a
Using pattern matching for instanceof
2 years ago
Josh Cummings
beab899c3d
Fix Import Order
2 years ago
1993heqiang
94c80bc2c6
Remove redundant code.
2 years ago
Jonas Bamberger
0d4e3f939a
Clean up SavedRequestAwareWrapper and related test
2 years ago
Jonas Bamberger
07f737b989
Return content-type from saved request
2 years ago
Marcus Da Coregio
7813a9ba26
Use default PathPatternParser instance
2 years ago
Josh Cummings
b0022a0ae8
Update Mockito Usage
...
Issue gh-13542
2 years ago
Josh Cummings
6c3636d780
Update Removed Usages
...
Issue gh-13544
2 years ago
Josh Cummings
40d61743b9
Replace Existing Continue Parameter
...
Closes gh-13438
2 years ago
Marcus Da Coregio
863aa5f65f
Fix Documented Default Value for AuthorizationFilter properties
...
Closes gh-13456
2 years ago
Marcus Da Coregio
2dee6218b5
Create NoOpAccessDeniedHandler
...
Closes gh-13109
3 years ago
Marcus Da Coregio
e35faa84f7
Create NoOpAuthenticationEntryPoint
...
Closes gh-13107
3 years ago
Claudio Nave
52e12ad64b
Replace deprecated methods
3 years ago
Evgeniy Cheban
0cefb27928
Simplify RequestMatcherDelegatingAuthorizationManager.Builder matcher registration
...
Closes gh-11624
3 years ago
Cedomir Igaly
dd469ac2a0
Assert is missing object. It was useless before Spring Framework 6.1, and will not compile on 6.1
3 years ago
Krzysztof Krason
9b603b99ab
Using modern Java features
3 years ago
Kandaguru17
7e01ebdd92
Remove LazyCsrfTokenRepository usage
...
Closes gh-13194
3 years ago
Christoph Zuleger
06e58e4c34
Update JavaDoc of BasicAuthenticationFilter
...
Remove deprecated hint to use Digest Auth in favor of Basic Auth.
3 years ago
Marcus Da Coregio
a53cbb838b
Polish
...
Issue gh-13155
3 years ago
joerg-richter-5234
8287289bcb
Fix XContentTypeOptionsServerHttpHeadersWriter
...
set constant value to X-Content-Type-Options
Closes gh-13155
3 years ago
Josh Cummings
4c5bf3bdf5
Polish
...
Use StringUtils#hasText
PR gh-13179
3 years ago
Dennis Frommknecht
af233a2a00
Use consistent list of micrometer tags in web observation handler
...
The tag `spring.security.reached.filter.name` is only set if a
filter-name is available, otherwise the tag is omitted entirely. This
leads to issues with metric-exporters that don't support dynamic tags,
but rather expect tag-names of a metric to be always the same. The most
prominent example is the Prometheus-exporter.
Instead of omitting the tag if no filer-name is set, a none-value is
applied instead, making the tag-list consistent in all cases
Closes gh-13179
3 years ago
Josh Cummings
e033e347b4
Remove Redundant Close
...
Closes gh-12787
3 years ago
Josh Cummings
5d903b5b71
Enforce start happens-before stop
...
Closes gh-13133
3 years ago
Steve Riesenberg
07b884a2cb
Add Set-Cookie header value for XSRF-TOKEN
...
This commit fixes an issue where using HttpServletResponse#setHeader
causes previous header values to be overwritten.
Closes gh-13075
3 years ago
Marcus Da Coregio
2d52fb8e4b
Clear Repository on Logout
3 years ago
Marcus Da Coregio
01d1e20dc3
Deprecate shouldFilterAllDispatcherTypes
...
Closes gh-12138
3 years ago
Josh Cummings
02345b97ff
Polish Observation Event Names
...
Issue gh-12811
3 years ago
bvn13
59ba7f5388
Shorten Observation Event Names
...
Closes gh-12811
3 years ago
Christian Marck
442faccb5f
Avoid NPE in FilterInvocation
...
Handle unknown headers in dummy request wrapper.
Closes gh-12998
3 years ago
Josh Cummings
6db2b0dcd0
Align Filter Chain Observability Lineage
...
Closes gh-12849
3 years ago
Christian Schuster
6791f3208e
Add factory class for RequestMatcher composition
...
Closes gh-12751
3 years ago