Max Batischev
fd267dfb71
Add Support JdbcPublicKeyCredentialUserEntityRepository
...
Closes gh-16224
1 year ago
Max Batischev
7b07ef5ff3
Add Support JdbcUserCredentialRepository
...
Closes gh-16224
1 year ago
Max Batischev
38523faaa0
Remove Unused loggers
...
Closes gh-16319
1 year ago
Max Batischev
e9bdb5b96e
Polish SecurityFilterChain Validation
...
Issue gh-15982
1 year ago
Josh Cummings
1104b45832
Polish SessionLimit
...
- Move to the web.authentication.session package since it is only needed
by web.authentication.session elements and does not access any other web
element itself.
- Add Kotlin support
- Add documentation
Issue gh-16206
1 year ago
Claudenir Machado
1864577e98
Address SessionLimitStrategy
...
Closes gh-16206
1 year ago
Josh Cummings
3eeb4317f6
Add setFavorRelativeUris
...
This places the new functionality behind a setting so that
we can remain passive until we can change the setting in
the next major release.
Issue gh-7273
1 year ago
Michal Okosy
7848b959da
Use relative URLs in /login redirects
...
Closes gh-7273
1 year ago
Josh Cummings
27c2a8ad11
Add Serializable Compatibility to Web Authentication Exceptions
...
Issue gh-16276
1 year ago
Yoshikazu Nojima
d7d5253607
Change attestation in PublicKeyCredentialCreationOptions to none
...
The attestation option in PublicKeyCredentialCreationOptions is a
parameter that controls whether to request attestation from the security key.
However, Spring Security Passkeys currently doesn't implement attestation verification.
Therefore, requesting attestation is unnecessary.
Specifying `direct` to request attestation may trigger browsers to
display additional privacy related dialog to users, so it is best to
avoid specifying `direct` unnecessarily.
1 year ago
Rob Winch
6a0b683e60
StrictFirewallHttpRequest.buid returns StrictFirewallHttpRequest
...
Closes gh-16069
1 year ago
Josh Cummings
4cbaabb239
Added Testing
...
Issue gh-16177
1 year ago
DingHao
f565b23b51
Restore Method Parameter Inheritance Support
...
Closes gh-16177
1 year ago
12OneTwo12
d39e329234
Add @inheritDoc to sessionIdChanged method
...
Closes gh-16211
1 year ago
Josh Cummings
96a9cf0d2d
Restore Previous Behavior for Servlet 5
...
Closes gh-16173
1 year ago
Rob Winch
9c3b11914d
webauthn registerCredential returns transports
...
The webauthn support previously did not pass the transports to webauthn4j.
This meant that the result of
Webauthn4jRelyingPartyOperations.registerCredential did not have any
transports either.
This commit ensures that the transports are passed to the webauth4j lib
and then returned in the result of registerCredential.
Closes gh-16084
1 year ago
DingHao
dc82a6e97e
Remove the cache since UniqueSecurityAnnotationScanner has cached annotations internally
1 year ago
Daniel Garnier-Moiroux
46fe0124ba
Add RuntimeHints for webauthn Javascript resource
1 year ago
Joe Grandja
fa5fc6dd62
Fix checkstyle errors for toLower/toUpperCase usage
1 year ago
Joe Grandja
a8c4d6cead
Require Locale argument for toLower/toUpperCase usage
1 year ago
Joe Grandja
a7bf8f7cc6
Require Locale argument for toLower/toUpperCase usage
1 year ago
Steve Riesenberg
285d16b046
Polish IpAddressMatcher
...
(cherry picked from commit 83a79159b8 )
1 year ago
Steve Riesenberg
ddf4542a9e
Add hasText assertion to IpAddressMatcher constructor
...
Issue gh-15527
(cherry picked from commit 3a29819651 )
1 year ago
Steve Riesenberg
554df6fab6
Fix NPE in IpAddressMatcher
...
Closes gh-15527
(cherry picked from commit 52de894c3c )
1 year ago
Joe Grandja
0eaffb37e7
Require Locale argument for toLower/toUpperCase usage
1 year ago
Steve Riesenberg
83a79159b8
Polish IpAddressMatcher
1 year ago
Steve Riesenberg
3a29819651
Add hasText assertion to IpAddressMatcher constructor
...
Issue gh-15527
1 year ago
Steve Riesenberg
52de894c3c
Fix NPE in IpAddressMatcher
...
Closes gh-15527
1 year ago
Daniel Garnier-Moiroux
a1526361b6
webauthn: introduce DefaultResourcesFilter#webauthn
1 year ago
nomoreFt
8f1c892fb7
Remove unnecessary parentheses and add static final field
1 year ago
DingHao
055ec57737
Fix not exist class in WebFilterChainProxy java doc
1 year ago
Josh Cummings
f46e56de78
Improve Error Message for Conflicting Filter Chains
...
Closes gh-15874
1 year ago
Tran Ngoc Nhan
571c7c81a4
Fix typo
1 year ago
Tran Ngoc Nhan
ab93541926
Simplify condition in some methods
1 year ago
Tran Ngoc Nhan
e76de931ce
Polish Optional usage
1 year ago
Tran Ngoc Nhan
ffed4ea1dc
Polish diamond usage
1 year ago
Josh Cummings
981fbd5c2c
Polish Tests
...
Closes gh-14768
1 year ago
DingHao
308e408b13
Polish DelegatingAuthenticationConverter
1 year ago
DingHao
1399a82ea9
Return Null Request When Cookie Is Malformed
...
Closes gh-15905
1 year ago
Joe Grandja
ec38848b20
Fix invalid windows character
1 year ago
Rob Winch
0e257b56ce
Add Firewall for WebFlux
...
Closes gh-15967
1 year ago
Rob Winch
4ce7cde155
Add Firewall for WebFlux
...
Closes gh-15967
1 year ago
Rob Winch
f689257dc4
Fix unused import
1 year ago
Rob Winch
8a0a5e2647
Format
1 year ago
Rob Winch
c461abd5da
Remove unnecessary WebauthnJackson2Module usage
...
HttpMessageConverterAuthenticationSuccessHandler does not need to use
WebauthnJacksonModule
1 year ago
Rob Winch
6d7df007dd
Remove non-ascii characters
...
Attempt fix windows format error
1 year ago
Rob Winch
5736f0897e
Remove imports for Javadoc Only Usage
1 year ago
Rob Winch
0bb406aaab
Run format again
1 year ago
Rob Winch
7f26e54d07
Remove §
...
See if this fixes format in windows
1 year ago
Rob Winch
b0e8730d70
Add Passkeys Support
...
Closes gh-13305
1 year ago