4702 Commits (c8d45397fe0fb92f8a11c2c0540d0cb55990da1d)
 

Author SHA1 Message Date
Luke Taylor 74daa68691 SEC-1796: Check for annotated annotations at class/interface level. Previously only the specific security annotation was checked for. By delegating to Spring's AnnotationUtils, custom annotations carrying the security annotation are also detected. 15 years ago
Luke Taylor 8ce4d326f5 Update HttpClient to 4.1.2 and removed incorrect bundlor references to commons version. 15 years ago
Luke Taylor 0120643721 SEC-1794: Convert OpenIDAuthenticationStatus to an enum. 15 years ago
Luke Taylor 0c2a950fa0 SEC-1788: Avoid unnecessary call to getPreAuthenticatedPrincipal() in AbstractPreAuthenticatedProcessingFilter when not checking for principal changes is not enabled. 15 years ago
Rob Winch 7399c9a7a5 SEC-1792: Fixed NullPointerException in RunAsUserToken#toString() 15 years ago
Rob Winch dfd467f26e cleaned imports in RunAsUserToken 15 years ago
Luke Taylor 7e44580c75 Minor refactoring of aspects tests. 15 years ago
Luke Taylor 8740efc0f5 Added constructor injection options to ConcurrentSessionFilter 15 years ago
Luke Taylor a1c714cff4 SEC-1754: Added an InvalidSessionStrategy to allow SessionManagementFilter to delegate out the behaviour when an invalid session identifier is submitted. 15 years ago
Luke Taylor ac3d8b25f2 Expand LDAP authentication FAQ with information about bind authentication and unreadable password attributes. 15 years ago
Luke Taylor 8440743108 Remove Sql query objects from JdbcTokenRepositoryImpl in favour of direct JdbcTemplate use. 15 years ago
Luke Taylor 89fa771093 SEC-1753: Cater for missing DiscoveryInformation object in OpenID4JavaConsumer.endConsumption. 15 years ago
Luke Taylor 700fa9e0b6 SEC-1772: remote URL decoding of targetUrlParameter in AbstractAuthenticationTargetUrlRequestHandler. 15 years ago
Luke Taylor de97bac85b SEC-1763: Prevent nested switches in SwitchUserFilter by calling attemptExitUser() before doing the switch. 15 years ago
Luke Taylor a504cfae1a SEC-1770: Call refreshLastRequest on the session registry rather than the SessionInformation object to make sure it works with alternative SessionRegistry implementations. 15 years ago
Luke Taylor d5946b81b4 Added FAQ on how to add ApacheDS entries to pom. 15 years ago
Luke Taylor c117c643df SEC-1782: Javadoc correction for LdapAuthenticationProvider. 15 years ago
Rob Winch 330f82f562 SEC-1777: Corrected log in HttpSessionSecurityContextRepository to reference itself instead of HttpSessionContextIntegrationFilter 15 years ago
Florian Fankhauser 2e83d98c8f SEC-1776: Corrected typo in manual 15 years ago
Rob Winch 825f0061fb SEC-1761: Support HttpOnly Flag for Cookies when using Servlet 3.0 15 years ago
Luke Taylor 56e86dd36f Adding assertions on constructor arg values. 15 years ago
Luke Taylor f92589f051 Extract a SecurityFilterChain interface and create a default implementation to facilitate other configuration options. 15 years ago
Luke Taylor 2d271666a4 Add constructors to facilitate constructor-based injection for required/shared bean properties. 15 years ago
Luke Taylor 73442125de SEC-1775: Removed internal use of UserAttribute class in AnonymousAuthenticationFilter. 15 years ago
Luke Taylor 5d20f57fa8 Import cleaning. 15 years ago
Luke Taylor b15475ab3d SEC-1771: Change TokenBasedRememberMeServices to obtain password from UserDetailsService if necessary. 15 years ago
Luke Taylor 737a9d1825 Improved toString methods on request wrappers. 15 years ago
Rob Winch 85807fdfd0 Removed @Overrides from method that implements interface instead of overriding superclass to resolve Java 1.5 error 15 years ago
Rob Winch c3a3a5bfbf Updated core.gradle to include crypto as referenced project in eclipse 15 years ago
Luke Taylor d253f5e109 SEC-1768: Use AopProxyUtils.ultimateTargetClass() to cater for the situation where the security interceptor is being applied to a proxy. 15 years ago
Luke Taylor 5a1ddc660b SEC-1768: Added tests to reproduce "double-proxying" issue combining intercept-methods and tx-annotation-driven. Problem is caused by use of ProxyFactoryBean with auto-proxying. 15 years ago
Luke Taylor b0a60a7ff2 Reset to snapshot version. 15 years ago
Luke Taylor 926be1ca78 Intermediate crypto release version. 15 years ago
Luke Taylor 2861a951aa Minor FAQ update on version info. 15 years ago
Luke Taylor 1f1faa6da0 Use getClass() in logger instantiation in AbstractLdapAuthenticationProvider. 15 years ago
Luke Taylor d9ccebd565 Add crypto module to LDAP bundlor template 15 years ago
Luke Taylor 89b7b2b935 SEC-1764: Remove use of Java 6 method Arrays.copyOfRange. 15 years ago
Luke Taylor 571bfc4869 Refactoring to use Utf8 encoder instead of String.getBytes("UTF-8"). 15 years ago
Luke Taylor 361b77685d Add crypto as an exported dependency of core in IDEA configuration. 15 years ago
Luke Taylor 2b8d4684a1 SEC-1764: Ensure password encoders use UTF-8 charset when creating strings from byte arrays. 15 years ago
Luke Taylor dc92baa257 Remove truststore settings from tutorial sample as they aren't required. 15 years ago
Luke Taylor e4ecdd55f6 Enable https in tutorial sample. 15 years ago
Luke Taylor 52c0ee6756 Improve error reporting of missing web classes in namespace handler. Now catches and logs the class-loading error. 15 years ago
Luke Taylor e27f655e9d SEC-1689: Re-instate crypto as separate library (for use in non-Spring Security apps), as well as packaging with core. 15 years ago
Luke Taylor ecfffaaa3f Make aspectj dependencies optional throughout and spring-jdbc/tx optional in core poms. Reduces exclusions required in third-party poms (e.g. spring-social). 15 years ago
Luke Taylor 80fd96df6d SEC-1650: Updates and corrections to tutorial sample to fit better with new tutorial. 15 years ago
Luke Taylor 685f12c5a0 SEC-1733: Support explicit zero netmask correctly. 15 years ago
Rob Winch c9b328d8c7 SEC-1757: Updated tutorial sample to state that listing of accounts is allowed by anyone and to display accounts for the different types of access to posting to Accounts 15 years ago
Luke Taylor 132163ec2e Add FAQ on accessing password from a UserDetailsService. 15 years ago
Luke Taylor f5f410ae3b Clean unused imports. 15 years ago