Rob Winch
dfaebfa63b
SEC-2872: CsrfAuthenticationStrategy Delay Saving CsrfToken
11 years ago
Rob Winch
f794272bac
SEC-2832: Add Tests
11 years ago
Stillglade
aa0a5b96ab
SEC-2832: Update request attributes with new CsrfToken
11 years ago
Rob Winch
27c7cd150b
SEC-2871: Polish README.adoc
11 years ago
shaehnel
b3d108fa44
SEC-2871: readme.txt->README.adoc
11 years ago
Rob Winch
975e4ec019
SEC-2078: AbstractPreAuthenticatedProcessingFilter requriesAuthentication support for non-String Principals
...
Previously, if the Principal returned by getPreAuthenticatedPrincipal was not a String,
it prevented requiresAuthentication from detecting when the Principal was the same.
This caused the need to authenticate the user for every request even when the Principal
did not change.
Now requiresAuthentication will check to see if the result of
getPreAuthenticatedPrincipal is equal to the current Authentication.getPrincipal().
11 years ago
Rob Winch
74f8534b17
SEC-2791: AbstractRememberMeServices sets the version
...
If the maxAge < 1 then the version must be 1 otherwise browsers ignore
the value.
11 years ago
Rob Winch
478a9650aa
SEC-2831: Regex/AntPath RequestMatcher handle invalid HTTP method
11 years ago
Rob Winch
b79ba12502
SEC-2777: Fix <header> attributes in doc
11 years ago
Rob Winch
72de17d79a
SEC-2822: Make EnableGlobalAuthenticationAutowiredConfigurer static Bean
...
This ensures that EnableGlobalAuthenticationAutowiredConfigurer is actually
used in newer versions of Spring. See SPR-12646
11 years ago
Rob Winch
e27200a255
SEC-2815: Delay looking up AuthenticationConfiguration
11 years ago
Rob Winch
c3f72f7b79
Merge pull request #160 from ractive/3.2.x
...
SEC-2812: Fix german translations in 3.2.x
11 years ago
james
b42cb9e3e1
SEC-2812: Fix german translations in 3.2.x
11 years ago
Rob Winch
b40088b73d
Merge pull request #155 from wilkinsona/powermock-upgrade
...
Upgrade to PowerMock 1.6.1
11 years ago
Andy Wilkinson
4116596a6c
Upgrade to PowerMock 1.6.1
...
The Platform would like to move to JUnit 4.12 but cannot do so at the
moment as Spring Security uses a version of PowerMock which is
incompatible with JUnit 4.12. This commit updates Spring Security to use
PowerMock 1.6.1 with is compatible with JUnit 4.12.
11 years ago
Christopher Pelloux
9de369c25f
SEC-2800 Documentation typo in class name
11 years ago
Rob Winch
bf2d2d4597
SEC-2773: Add Test for static delegatingApplicationListener
11 years ago
Oliver Gierke
c05f27af6c
SEC-2773: Prevent premature container initialization in WebSecurityConfiguration.
...
Changed the bean definition method for the DelegatingApplicationListener
to be static to avoid the need to instantiate the configuration class which
caused further premature initializations to satisfy the dependencies
expressed in setFilterChainProxySecurityConfigurer(…).
11 years ago
Rob Winch
cdac4d990b
SEC-2747: Remove spring-core dependency from spring-security-crypto
11 years ago
Rob Winch
db66843e0b
SEC-2749: CsrfConfigurer.requireCsrfProtectionMatcher correct null check
11 years ago
Rob Winch
c36cc88ac4
SEC-2150: Support class level annotations on Spring Data Repositories
11 years ago
Rob Winch
7d82349b1e
SEC-2150: Add tests to verify JSR-250 Spec behavior
11 years ago
Rob Winch
b6ab9c85e9
SEC-2682: DelegatingSecurityContextRunnable/Callable delegate toString()
11 years ago
Rob Winch
29a8da4aa6
SEC-2574: Fix Bundlr
11 years ago
Rob Winch
b71989ecde
SEC-2574: JavaConfig default SessionRegistry processes SessionDestroyedEvents
11 years ago
Rob Winch
eeef91498a
SEC-2674: Documentation refers to httpStrictTransportSecurity() instead of hsts()
11 years ago
Spring Buildmaster
91bf099b01
Next development version
12 years ago
Rob Winch
137589325d
SEC-2547: Update to cas-client-core-3.3.3
12 years ago
Rob Winch
0a184a8d79
SEC-2697: Fix logging of Spring Version Check
12 years ago
Rob Winch
2cb99f0791
SEC-2688: CAS Proxy Ticket Authentication uses Service for host & port
12 years ago
Rob Winch
d85a0a20bc
SEC-2595: @EnableGlobalMethodSecurity AspectJ tweaks for Spring 3.2.x
12 years ago
Rob Winch
0a45d3170c
SEC-2595: @EnableGlobalMethodSecurity AspectJ fixes
12 years ago
Rob Winch
89c5c56849
SEC-2599: HttpSessionEventPublisher get required ApplicationContext
...
In order to get better error messages (avoid NullPointerException) the
HttpSessionEventPublisher now gets the required ApplicationContext which
throws an IllegalStateException with a good error message.
12 years ago
Rob Winch
47acf17323
SEC-2588: Javadoc fix channelSecurity->requiresChannel
12 years ago
Rob Winch
52c585aef1
SEC-2665: Fix samples/ldap-jc link in reference
12 years ago
Rob Winch
89d80ed5c9
SEC-2683: Correct spelling of assignamble in AuthenticationPrincipalResolver Exception
12 years ago
Mirko Zeibig
85a37bdc02
SEC-2656: Fix <frame-options> with whitelist strategy
12 years ago
Rob Winch
fb1f2dc888
Next development version ldap/pom.xml
12 years ago
Rob Winch
d5842f949b
SEC-2657: Test for multi dynamic ports for LDAP Java Config
12 years ago
Rob Winch
3e3d819526
SEC-2660: Move config integration-test *.groovy to groovy source folder
12 years ago
Rob Winch
143c513f5c
SEC-2659: ApacheDSContainer fails on import multiple ldif
12 years ago
Rob Winch
8eb89e3f12
SEC-2658: Java Config triggers usePasswordAttrCompare to be set
12 years ago
Rob Winch
bdde468e7d
SEC-2657: LdapAuthenticationProviderConfigurer find available port
12 years ago
Rob Winch
f574f2a2ac
SEC-2618: LdapAuthenticationProviderConfigurer passwordAttribute null check
...
If LdapAuthenticationProviderConfigurer passwordAttribute is null, do not
set on the PasswordComparisonAuthenticator
12 years ago
Rob Winch
439a15b108
SEC-2647: IntelliJ testSourceDirs
12 years ago
Rob Winch
44fbf678bb
Fix jdbc-jc to work with tomcat gradle plugin
...
It is necessary to ensure that src/main/webapp exists to ensure the
application starts with the Tomcat Gradle Plugin.
This commit adds a Manifest file to src/main/webapp/META-INF to ensure
that git contains the otherwise empty directory.
12 years ago
Rob Winch
9c94ef358d
SEC-2617: Add JSTL to sample poms
12 years ago
Rob Winch
655ad90813
SEC-2617: Fix JSTL Samples
12 years ago
Rob Winch
a0ee80bc61
SEC-2650: Fix Jetty Warn NoInitialContextException on shutdown
12 years ago
Rob Winch
6b977d9b4b
SEC-2649: Update to Tomcat 7.0.54
12 years ago