Josh Cummings
953c9294d0
Initial SAML Deprecation Preparation Steps
...
- Stop using Converter constructors
- Replace Saml2AuthenticationRequestContextResolver and
Saml2AuthenticationRequestFactory with
Saml2AuthenticationRequestResolver
Issue gh-11077
3 years ago
Josh Cummings
ba8f344ccb
Add AuthenticationServiceException Reactive Preparation Steps
...
Issue gh-9429
Issue gh-12132
3 years ago
Ger Roza
8315545144
Update RP-Initiated Logout target URLs.
...
The URLs we're using are not actually pointing to the OIDC RP-Initiated Logout Specs.
Fixes: gh-12081
3 years ago
Marcus Da Coregio
7cbb9e82f9
Document how to opt-in for SHA256 in RememberMe
...
Closes gh-12097
3 years ago
Josh Cummings
39f4fcd5f2
Add AuthenticationEntryPointFailureHandler Preparation Steps
...
Issue gh-9429
3 years ago
Josh Cummings
ac7f726a24
Add RunAsManager Preparation Steps
...
Closes gh-11337
3 years ago
Josh Cummings
c5badbc631
Add AccessDecisionManager Preparation Steps
...
Issue gh-11337
3 years ago
Josh Cummings
86c9d5cfbe
Remove Stray Horizontal Rules
...
Issue gh-11337
3 years ago
Rob Winch
4112adf6a0
Document Configure Default CsrfTOken BREACH Protection
...
Closes gh-12107
3 years ago
Rob Winch
96d7c78b67
Polish Document Defer load CsrfToken
...
Issue gh-12105
3 years ago
Rob Winch
d860775b45
Document Defer load CsrfToken
...
Closes gh-12105
3 years ago
Josh Cummings
4938c394e4
Move Opt-out Steps
...
Closes gh-12104
3 years ago
Josh Cummings
8da916fa1c
Add Request Security Preparation Steps
...
Issue gh-11337
3 years ago
Josh Cummings
e900ca3a86
Polish Method Security Preparation Steps
...
- Add instruction to declare 5.8 defaults
Issue gh-11337
3 years ago
Josh Cummings
b4974bbce9
Polish Message Security Preparation Steps
...
- Added step to declare the 5.8 default in case later preparation steps
cannot be taken yet
Issue gh-11337
3 years ago
Josh Cummings
31a1486b88
Add Message Security Preparation Steps
...
Issue gh-11337
3 years ago
Rob Winch
5721b0351e
Polish RequestCache continue Kolin Configuration
...
Issue gh-12089
3 years ago
Rob Winch
aac1261f0c
Document Migration to SecurityContextHolderFilter
...
Closes gh-12098
3 years ago
Josh Cummings
1dd13e69a4
Standardize Preparation Guide Layout
...
Closes gh-12096
3 years ago
Josh Cummings
2a95a24390
Add Link to 6.0 Migration Guide
...
Issue gh-12093
3 years ago
Rob Winch
24cc7ff178
Document Saved Requests Migration
...
Closes gh-12089
3 years ago
Rob Winch
c17e258a6f
Document Saved Requests
...
Closes gh-12088
3 years ago
Josh Cummings
f6731e89db
Polish Method Security Preparation Steps
3 years ago
Josh Cummings
04fa5af794
Add Missing Doc Header
...
The EnableMethodSecurity section
3 years ago
Josh Cummings
e505bc3af4
Add Method Security Preparation Steps
3 years ago
Steve Riesenberg
5a55987d6e
Add links to reference in What's New for 5.8
...
Issue gh-4001
Issue gh-11959
3 years ago
Josh Cummings
59c4538798
Update What's New
...
Closes gh-12021
3 years ago
Joe Grandja
ffbcaca24a
Update reference for PasswordEncoders
...
Issue gh-10506
3 years ago
Marcus Da Coregio
4b6fed0667
Add static factory method to AntPathRequestMather and RegexRequestMatcher
...
Closes gh-11938
3 years ago
Steve Riesenberg
f462134e87
Add reactive support for BREACH
...
Closes gh-11959
3 years ago
Marcus Da Coregio
f3321c256c
Add XML support for shouldFilterAllDispatcherTypes
...
Closes gh-11492
3 years ago
Steve Riesenberg
dce1c30522
Add support for BREACH
...
Closes gh-4001
3 years ago
Steve Riesenberg
c1fcf275d9
Update What's New for 5.8
...
Issue gh-11952
3 years ago
Marcus Da Coregio
ace8caa182
Remove mvcMatchers usage from docs
...
Issue gh-11347
3 years ago
Steve Riesenberg
475b3bb6bb
Add deferred CsrfTokenRepository.loadDeferredToken
...
* Move DeferredCsrfToken to top-level and implement Supplier<CsrfToken>
* Move RepositoryDeferredCsrfToken to top-level and make package-private
* Add CsrfTokenRepository.loadToken(HttpServletRequest, HttpServletResponse)
* Update CsrfFilter
* Rename CsrfTokenRepositoryRequestHandler to CsrfTokenRequestAttributeHandler
Issue gh-11892
Closes gh-11918
3 years ago
Daniel Garnier-Moiroux
0e215a21ad
Add X-Xss-Protection headerValue to XML config
...
Issue gh-9631
3 years ago
Marcus Da Coregio
039e0328e1
Simplify Java Configuration RequestMatcher Usage
...
If Spring MVC is present in the classpath, use MvcRequestMatcher by default. This commit also adds a new securityMatcher method in HttpSecurity
Closes gh-11347
Closes gh-9159
3 years ago
Daniel Garnier-Moiroux
bf59d7c374
Update What's New for 5.8
3 years ago
Steve Riesenberg
46696a9226
CsrfTokenRequestHandler extends CsrfTokenRequestResolver
...
Closes gh-11896
3 years ago
Rob Winch
d94677f87e
CsrfTokenRequestAttributeHandler -> CsrfTokenRequestHandler
...
This renames CsrfTokenRequestAttributeHandler to CsrfTokenRequestHandler and
moves usage from CsrfFilter into CsrfTokenRequestHandler.
Closes gh-11892
3 years ago
Marcus Da Coregio
983ca6ea27
Update What's New for 5.8
3 years ago
Steve Riesenberg
8f44f74d44
Update What's New for 5.8
3 years ago
Steve Riesenberg
70eea8dc67
Update What's New for 5.8
3 years ago
Steve Riesenberg
355ef21117
Polish gh-11665
3 years ago
ch4mpy
1efb63387f
Add authentication converter for introspected tokens
...
Adds configurable authentication converter for resource-servers with
token introspection (something very similar to what
JwtAuthenticationConverter does for resource-servers with JWT decoder).
The new (Reactive)OpaqueTokenAuthenticationConverter is given
responsibility for converting successful token introspection result
into an Authentication instance (which is currently done by a private
methods of OpaqueTokenAuthenticationProvider and
OpaqueTokenReactiveAuthenticationManager).
The default (Reactive)OpaqueTokenAuthenticationConverter, behave the
same as current private convert(OAuth2AuthenticatedPrincipal principal,
String token) methods: map authorities from scope attribute and build a
BearerTokenAuthentication.
Closes gh-11661
3 years ago
Rob Winch
5ae492b1c1
Add What's New @WithMockUser Supported as Merged Annotation
3 years ago
Steve Riesenberg
86fbb8db07
Add new interfaces for CSRF request processing
...
Issue gh-4001
Issue gh-11456
3 years ago
Underground Hill
8b74bf9742
Updated reference to architecture page
...
In the context of Servlet Authentication page, "Architecture" should probably link to "Servlet Authentication Architecture" page
3 years ago
he1ex-tG
568277f8bc
Mistake in Kotlin code representation is fixed
3 years ago
Josh Cummings
0f58620643
Add AspectJ AuthorizationManager Support
...
Closes gh-11326
3 years ago