387 Commits (d9c9cd7f8482cc501162b703bdf93729e86b2daf)

Author SHA1 Message Date
Rob Winch 32e9239fd2 SEC-2320: AuthenticationPrincipal can be null on invalid type 13 years ago
Rob Winch b22acd0768 SEC-2314: AbstractSecurityWebApplicationInitializer.getSessionTrackingModes() uses EnumSet 13 years ago
Rob Winch 8e74407381 SEC-2296: HttpServletRequest.login should throw ServletException if already authenticated 13 years ago
Rob Winch e8ac11641b SEC-2297: Add DispatchType.ASYNC as default for AbstractSecurityWebApplicationInitializer 13 years ago
Rob Winch 43f4d01cf3 SEC-2292: Add test to assert CSRF bypass of methods is case sensitive 13 years ago
Rob Winch 6e9fb7930b SEC-2298: Add AuthenticationPrincipalArgumentResolver 13 years ago
Rob Winch 086056f191 SEC-2289: Make compatible with Spring 4 as well 13 years ago
Rob Winch 26166ef6e8 SEC-2272: CsrfRequestDataValueProcessor support Spring 4 and Spring 3 13 years ago
Rob Winch 3f69847a4e SEC-2286: Log invalid CSRF tokens at debug level 13 years ago
Rob Winch 33db440961 SEC-2129: AntPathRequestMatcher also supports case sensitive comparisions 13 years ago
Rob Winch 534989c8ea SEC-2103: Fix tests to verify debug logging instead of info 13 years ago
Rob Winch acb2b680d0 SEC-2103: Change log of no results to debug 13 years ago
Rob Winch 48283ec004 SEC-2276: Delay saving CsrfToken until token is accessed 13 years ago
Rob Winch e9bb9e766e SEC-1574: Add CSRF Support 13 years ago
Rob Winch 797df51264 SEC-2135: Support HttpServletRequest#changeSessionId() 13 years ago
Rob Winch 75fb971d23 SEC-2221: Fix the ignored media types to use includes instead of equals 13 years ago
Rob Winch 13da42ca1b SEC-2137: Allow disabling session fixation and enable concurrency control 13 years ago
Rob Winch 867f02e8ac SEC-2249: AbstractSecurityWebApplicationInitializer does not delegate WebApplicationInitializer 13 years ago
Rob Winch e8278f3b9b SEC-2249: AbstractSecurityWebApplicationInitializer allows register config 13 years ago
Rob Winch fdb73fac23 Remove @Override from interface define methods 13 years ago
Rob Winch 94a73fee37 SEC-2230: Polish scoping and finals 13 years ago
Rob Winch 606bddf598 SEC-2230: Add Header JavaConfig 13 years ago
Rob Winch c85328c5d1 SEC-2230: HTTP Strict Transport Security (HSTS)Add support for Strict 13 years ago
Rob Winch 8013cd54d6 SEC-2230: Added Cache Control support 13 years ago
Rob Winch 7b164bb5e1 SEC-2230: Polish pull request 13 years ago
Rob Winch 8acd205486 SEC-2232: HeaderFactory to HeaderWriter 13 years ago
Rob Winch fd754c5cab SEC-2098, SEC-2099: Fix build 13 years ago
Marten Deinum d0b40cd2ae - Created HeaderFactory abstraction 13 years ago
Marten Deinum 0adf5aea91 SEC-2098, SEC-2099: Created HeadersFilter 13 years ago
Rob Winch f5a30e55a3 SEC-2042: AbstractAuthenticationProcessingFilter supports RequestMatcher 13 years ago
Rob Winch 686a7a8d62 SEC-2223: Correct FirewalledRequest#reset() javadoc 13 years ago
Rob Winch 04b7d5ca08 SEC-2156: Only configures COOKIE instead of SSL 13 years ago
Rob Winch ac053dbda7 SEC-2156: AbstractSecurityWebApplicationInitializer configures SessionTrackingMode 13 years ago
Rob Winch 4411ae3ff6 SEC-2221: Add MediaTypeRequestMatcher 13 years ago
Rob Winch 59e8551279 Fix package tangles 13 years ago
Rob Winch e5c450a14c Merge in AbstractSecurityWebApplicationInitializerTests.groovy 13 years ago
Keesun Baik cf80cc88b5 SEC-2192: Create DEFAULT_FILTER_NAME 13 years ago
Rob Winch d0c4e6ca72 SEC-1953: Spring Security Java Config support 13 years ago
Rob Winch 7bc87cf13b SEC-2002: Polishing 13 years ago
Nicholas Williams d89ace26ab SEC-2002: Added events to notify of session ID change 13 years ago
Rob Winch 5f9dfb73be SEC-2111: Disable auto save of SecurityContext when response committed after startAsync invoked 13 years ago
Balazs Zagyvai 73ea8b5c05 SEC-2107: Fix Javadoc on methods of AbstractAuthenticationProcessingFilter 13 years ago
Rob Winch 9c4563285e SEC-1998: Async tests with SecurityContextHolderAwareReqeustFilter 13 years ago
Rob Winch c8d45397fe SEC-2079: Add Servlet 3 Authentication methods 13 years ago
Rob Winch d04cf5ea68 Remove unused FilterInvocation.DummyResponse 13 years ago
Rob Winch 1a650acbcc SEC-1998: DummyRequest extend HttpServletRequestWrapper 13 years ago
Rob Winch 3437ef714a SEC-1998: SecurityContextCallableProcessingInterceptor uses postProcess 13 years ago
Rob Winch 796de42105 Revert "SEC-2078: AbstractPreAuthenticatedProcessingFilter requriesAuthentication support for non-String Principals" 13 years ago
Rob Winch 70849aa8d2 Revert "SEC-2078: Updated Javadoc to reflect that updates to Principal will also trigger reauthentication" 13 years ago
Rob Winch ece4a0f067 SEC-2078: Updated Javadoc to reflect that updates to Principal will also trigger reauthentication 13 years ago