Ben Alex
|
08db4a1358
|
SEC-610: Reauthenticate even if AnonymousAuthenticationToken is present.
|
18 years ago |
Luke Taylor
|
843a20e691
|
Changed default namespace in config files to "security" for clarity.
|
18 years ago |
Luke Taylor
|
09c588a138
|
Removed unecessary check in additionalAuthenticationChecks() for null credentials in authentication object. Previous line already throws an exception if null is found.
|
18 years ago |
Luke Taylor
|
88e01624eb
|
SEC-560: Removed local password comparison form PasswordComparisonAuthenticator.
|
18 years ago |
Luke Taylor
|
0e1ae11fca
|
Tidying.
|
18 years ago |
Luke Taylor
|
292320bd33
|
SEC-607: Changed NtlmUsernamePasswordAuthenticationToken to make authenticated=true the default state when an instance is created. NtlmAwareLdapAuthenticator now rejects tokens with authenticated=false (e.g. if the token has been passed remotely).
|
18 years ago |
Luke Taylor
|
4f3a1739aa
|
Changed Ntlm filter to use SpringSecurityFilter base class.
|
18 years ago |
Luke Taylor
|
9e2f372bad
|
SEC-607: Deprecated InitialDirContextFactory and replaced it with SpringSecurityContextSource.
Also some refactoring of LdapUserDetailsManager to use a strategy for creating DNs from usernames.
|
18 years ago |
Luke Taylor
|
6d5773d177
|
Replaced creation of new list with Collections.EMPTY_LIST reference.
|
18 years ago |
Luke Taylor
|
1196381220
|
Remove "controls" property as it doesn't really make sense and has never been used.
|
18 years ago |
Luke Taylor
|
91e0a329f9
|
Upgrade to Spring LDAP 1.2 final.
|
18 years ago |
Luke Taylor
|
b1b3f585e4
|
Moved setter methods out of inner classes area.
|
18 years ago |
Luke Taylor
|
c485664ee7
|
Removed accidental use of autoboxing.
|
18 years ago |
Luke Taylor
|
3e3dac4050
|
SEC-600: Added extra test assertions on authentication details object after password change.
|
18 years ago |
Luke Taylor
|
cb237055ac
|
SEC-600: Added Jdbc implementation of UserDetailsManager
|
18 years ago |
Luke Taylor
|
81067840ef
|
SEC-485: Added calculateLoginLifetime method.
|
18 years ago |
Luke Taylor
|
b681952933
|
SEC-545: Added utility methods for checking if user has a particular role to existing AuthorityUtils class. Class may be renamed at some point as more functionality is added.
|
18 years ago |
Luke Taylor
|
315d4a247f
|
Added method to clear datasource field after use.
|
18 years ago |
Luke Taylor
|
910e63f83c
|
SEC-586: Implemented secure channel support in namespace configuration.
|
18 years ago |
Luke Taylor
|
c214f4a9bc
|
Simplified initialization of datasource.
|
18 years ago |
Luke Taylor
|
4f3bbb52f6
|
Pulled methods and fields up into AbstractFilterInvocationDefinitionSource to make it easier to query the map size etc, regardless of the specific type.
|
18 years ago |
Luke Taylor
|
28a138f8ec
|
Converted to use guard clause to reduce nesting.
|
18 years ago |
Luke Taylor
|
756be6fed3
|
Removed unnecessary constructor.
|
18 years ago |
Luke Taylor
|
964e6911a7
|
Added RememberMeServices to list of logout handlers.
|
18 years ago |
Luke Taylor
|
2856a6ba43
|
Allow configuration of embedded ldap server port through ldap namespace configuration. Changed default port from 3389 to avoid conflict with windows remote desktop (as reported by Ray Krueger in dev list).
|
18 years ago |
Luke Taylor
|
0e7dac6ca5
|
SEC-565: Refactoring of TokenBasedRememberMeServices. Changed arguments to makeValidSignature so that it could be used from both places where a signature is required and refactored the class to extend AbstractRememberMeServices. The method processAutoLoginCookie now returns a UserDetails, rather than username, as the UserDetails is needed in TokenBasedRememberMeServices.
|
18 years ago |
Luke Taylor
|
1a5ef2dece
|
SEC-588: Completed JdbcTokenRepositoryImpl and added extra update method to PersistentTokenRepository interface (additional files from failed commit).
|
18 years ago |
Luke Taylor
|
7caa1587b3
|
SEC-588: Completed JdbcTokenRepositoryImpl and added extra update method to PersistentTokenRepository interface.
|
18 years ago |
Scott Battaglia
|
87a864619d
|
SEC-592
fixed failing test due to thinking a null value should be provided.
|
18 years ago |
Scott Battaglia
|
981f185575
|
SEC-592
implemented NullStatelessTicketCache and test cases and made it the default for CasAuthenticationProvider.
|
18 years ago |
Luke Taylor
|
0a50cd67ce
|
Tidied up logic for setting token repository in RememberMeBeanDefinitionParser. Plus some tinkering with attributes in rnc file.
|
18 years ago |
Luke Taylor
|
9fa32bac7c
|
SEC-578: Set FilterInvocationDefinitionSource field in FilterChainProxy to null after it has been converted to a map of paths->filters.
|
18 years ago |
Luke Taylor
|
9f2bc9a842
|
SEC-582: Namespace configuration implementation for remember-me support.
|
18 years ago |
Luke Taylor
|
b868143fb1
|
Make sure "start" is called even if working directory is already set.
|
18 years ago |
Luke Taylor
|
7ad8e2acf0
|
SEC-591: Removed default NullRememberMeServices in RememberMeProcessingFilter
|
18 years ago |
Luke Taylor
|
4c44bd782f
|
SEC-588: Added extra tests to check cookie values.
|
19 years ago |
Luke Taylor
|
55b1f9348d
|
SEC-588: PersistentTokenBasedRememberMeServices implementation.
|
19 years ago |
Luke Taylor
|
8b199d38ed
|
Refactored autoLogin method to reduce nesting of conditionals and loops.
|
19 years ago |
Luke Taylor
|
d7b6ca281a
|
Removed unused "autodetect" method.
|
19 years ago |
Luke Taylor
|
43fc8e2660
|
Added Id keyword for all java files
|
19 years ago |
Luke Taylor
|
d3b165749f
|
SEC-583: Implementation of namespace config for concurrent session support.
Also some minor adjustments to ordering of different http features in schema.
|
19 years ago |
Luke Taylor
|
334d55b12e
|
Tidying.
|
19 years ago |
Luke Taylor
|
685d74d81b
|
FilterSecurityInterceptor is now configured through ConfigUtils, rather than by autowiring.
|
19 years ago |
Luke Taylor
|
0185dc5a90
|
Moved registration of ProviderManager bean to ConfigUtils.
|
19 years ago |
Luke Taylor
|
06ce4b79e9
|
SEC-584: Remove use of default SessionRegistryImpl.
|
19 years ago |
Luke Taylor
|
0cdac4912a
|
Changed to use a BeanReference when creating default login page to prevent duplication of filter bean.
|
19 years ago |
Luke Taylor
|
3d9ea49d19
|
SEC-585: Made expiredUrl optional.
Also implemented Ordered interface for use in namespace configuration.
|
19 years ago |
Luke Taylor
|
55ef50a4df
|
Added checking of path ordering to FilterChainProxy to detect misplaced universal match ("/**").
|
19 years ago |
Luke Taylor
|
1bcb62af2e
|
Remove use of autoconfig, as it was really just a conveniece for creating default access and authentication managers.
|
19 years ago |
Luke Taylor
|
700de0d388
|
Tidying.
|
19 years ago |