1408 Commits (d3d8f7d60fea379130bfdec1184b6df2ba1cd7f9)

Author SHA1 Message Date
Josh Cummings 99a87179dd
Instrument Filter Chain 3 years ago
Steve Riesenberg 8bd25f90e4
Polish XorServerCsrfTokenRequestAttributeHandlerTests 3 years ago
Steve Riesenberg 804f20045e
Polish XorCsrfTokenRequestAttributeHandlerTests 3 years ago
Steve Riesenberg 05e4a1dd20
Cache Xor CsrfToken 3 years ago
Marcus Da Coregio 4b6fed0667 Add static factory method to AntPathRequestMather and RegexRequestMatcher 4 years ago
Daniel Garnier-Moiroux 27059ced87
Default X-Xss-Protection header value to "0" 4 years ago
Steve Riesenberg f462134e87
Add reactive support for BREACH 4 years ago
Steve Riesenberg f4ca90e719
Add reactive interfaces for CSRF request handling 4 years ago
Marcus Da Coregio c4d23f2b49 Use MvcRequestMatcher by default if Spring MVC is present 4 years ago
Josh Cummings 380a6a2564
Polish SecurityContextHolderStrategy Usage 4 years ago
Josh Cummings f16d47c7b5
Polish DefaultHttpSecurityExpressionHandler 4 years ago
Josh Cummings 4ddec07d0e
Add default AuthorizationManager 4 years ago
Steve Riesenberg ee9449dbfe
Fix tests for deferred CSRF tokens 4 years ago
Steve Riesenberg 521cdfd738
Use correct servlet imports 4 years ago
Steve Riesenberg dce1c30522
Add support for BREACH 4 years ago
Steve Riesenberg 475b3bb6bb
Add deferred CsrfTokenRepository.loadDeferredToken 4 years ago
Daniel Garnier-Moiroux 0e215a21ad
Add X-Xss-Protection headerValue to XML config 4 years ago
Marcus Da Coregio 039e0328e1 Simplify Java Configuration RequestMatcher Usage 4 years ago
Marcus Da Coregio 64a19de4dc Deprecate HPKP security header 4 years ago
Rob Winch 4479cefade Default Require Explicit Session Management = true 4 years ago
Daniel Garnier-Moiroux 93250013e4
Make X-Xss-Protection configurable through ServerHttpSecurity 4 years ago
Steve Riesenberg e0e6467d9b
Remove UsernamePasswordAuthenticationToken check 4 years ago
shazin 1e0e9a2c98
Allow authenticationIsRequired to be overridden 4 years ago
Steve Riesenberg 46696a9226
CsrfTokenRequestHandler extends CsrfTokenRequestResolver 4 years ago
Steve Riesenberg 3c66ef6305
Change default SecurityContextRepository 4 years ago
Steve Riesenberg d140d95305
Fix assertion in NullSecurityContextRepository 4 years ago
Steve Riesenberg 5d757919a2
Add SecurityContextHolderStrategy to new repository 4 years ago
Rob Winch d94677f87e CsrfTokenRequestAttributeHandler -> CsrfTokenRequestHandler 4 years ago
Josh Cummings 2a487ae7f8
Updated hashcode and equals 4 years ago
Josh Cummings 3f8503f1b4
Deprecate AccessDecisionManager et al 4 years ago
Steve Riesenberg 088ebe2e00
Default CsrfTokenRequestProcessor.csrfRequestAttributeName = _csrf 4 years ago
Steve Riesenberg 86fbb8db07 Add new interfaces for CSRF request processing 4 years ago
Rob Winch 8cb97a090b Default CsrfFilter.csrfRequestAttributeName = _csrf 4 years ago
Steve Riesenberg 0aa5850d22
Fix formatting 4 years ago
Rob Winch 2efc8dcd15 Default Require Explicit Save SecurityContext 4 years ago
Rob Winch f84f08c4b9 Default HttpSessionRequestCache.matchingRequestParameterName=continue 4 years ago
Bert Vanwolleghem a5351f3d89
LogoutPageGeneratingWebFilter Uses Context Path 4 years ago
shinD 4ff0724c87
slight improvement in HttpSessionRequestCache 4 years ago
Rob Winch 2fb625db84 Remove mockito deprecations 4 years ago
cyb3r4nt 1d555b62e3 Fix IP address parse error msg in IpAddressMatcher 4 years ago
Rob Winch 8ad20b1768 Add CsrfFilter.csrfRequestAttributeName 4 years ago
Rob Winch 2aedf5899b LazyCsrfTokenRepository#loadToken Supports Deferring Delegation 4 years ago
Rob Winch 5b64526ba9 Add CsrfFilter.csrfRequestAttributeName 4 years ago
Rob Winch 666f175225 LazyCsrfTokenRepository#loadToken Supports Deferring Delegation 4 years ago
Marcus Da Coregio ead587c597 Consistently handle RequestRejectedException if it is wrapped 4 years ago
Marcus Da Coregio 6a2ca52aae Consistently handle RequestRejectedException if it is wrapped 4 years ago
Marcus Da Coregio 24bb83e2c7 Consistently handle RequestRejectedException if it is wrapped 4 years ago
Marcus Da Coregio 1c4d6ed098 Consistently handle RequestRejectedException if it is wrapped 4 years ago
Rob Winch c23324e7a7 RequestAttributeSecurityContextRepository never null SecurityContext 4 years ago
Rob Winch 269c711a64 RequestAttributeSecurityContextRepository never null SecurityContext 4 years ago