1501 Commits (f1824f8a5d9bcbb4fd395740bdd6d8ccc6354d2f)

Author SHA1 Message Date
Marcus Da Coregio 99d6d21554 Apply SecurityContextHolderFilter to all dispatcher types 3 years ago
Josh Cummings 701f754e37
Cast FilterChainObservationContext Safely 3 years ago
Steve Riesenberg fd547321e8
Default to XorCsrfTokenRequestAttributeHandler 3 years ago
Steve Riesenberg 2ed7cff643
Check for existing token before clearing 3 years ago
Josh Cummings 24860d9fb0
Observe Filter Start and Stop 3 years ago
Josh Cummings e08ed89403 Polish Span and Meter Names 3 years ago
Marcus Da Coregio 063f06e7bf Register FilterChainProxy for all dispatcher types 3 years ago
Steve Riesenberg 57b163bb78
Polish gh-12141 3 years ago
Marcus Da Coregio 2a261e0583 Add Jakarta WebSocket 2.1 test dependency to spring-security-web 3 years ago
Marcus Da Coregio 3b5d19c8a4 Adapt to Servlet API 6 changes and support Jakarta WebSocket 2.1 3 years ago
Steve Riesenberg 6b0ed0205b
Re-generate tokens in CookieCsrfTokenRepository 3 years ago
Marcus Da Coregio 1f481aafff
Fix AuthorizationFilter incorrectly extending OncePerRequestFilter 3 years ago
David Becker 2b426872a3
Use InetSocketAddress#getHostString 3 years ago
Steve Riesenberg 8554e70c09
Remove deprecated loadContext(request) 3 years ago
Steve Riesenberg e238b721bb
Fix imports in DelegatingSecurityContextRepository 3 years ago
Steve Riesenberg acc35aeb18
Add DelegatingSecurityContextRepository 3 years ago
Steve Riesenberg c75ca10900
Add DeferredSecurityContext 3 years ago
Josh Cummings f4cc27c375
Change Default for (Server)AuthenticationEntryPointFailureHandler 3 years ago
Josh Cummings 099aaa33ff
Remove Deprecation Markers 3 years ago
Daniel Garnier-Moiroux 200b7fecd3
Add (Server)AuthenticationEntryPointFailureHandlerAdapter 3 years ago
Evgeniy Cheban 56b9badcfe
AnonymousAuthenticationFilter should cache its Supplier<SecurityContext> 3 years ago
Steve Riesenberg 45a963a011
Remove CsrfWebFilter.setTokenFromMultipartDataEnabled 3 years ago
Joe Grandja 753e113a13 RequestMatcherDelegatingAuthorizationManager defaults to deny 3 years ago
Steve Riesenberg 2407d07890
Default to Xor CSRF tokens in CsrfWebFilter 3 years ago
Steve Riesenberg 2a2051cd7b
Default to Xor CSRF tokens in CsrfFilter 3 years ago
Joe Grandja 185991a606 Revert "Add default AuthorizationManager" 3 years ago
Josh Cummings 2713075d08
Mark Observations with Firewall Failures 3 years ago
Josh Cummings 46ab84684b
Mark Observations with CSRF Failures 3 years ago
Josh Cummings 99a87179dd
Instrument Filter Chain 3 years ago
Steve Riesenberg 8bd25f90e4
Polish XorServerCsrfTokenRequestAttributeHandlerTests 3 years ago
Steve Riesenberg 804f20045e
Polish XorCsrfTokenRequestAttributeHandlerTests 3 years ago
Steve Riesenberg 05e4a1dd20
Cache Xor CsrfToken 3 years ago
Marcus Da Coregio 4b6fed0667 Add static factory method to AntPathRequestMather and RegexRequestMatcher 3 years ago
Daniel Garnier-Moiroux 27059ced87
Default X-Xss-Protection header value to "0" 3 years ago
Steve Riesenberg f462134e87
Add reactive support for BREACH 3 years ago
Steve Riesenberg f4ca90e719
Add reactive interfaces for CSRF request handling 3 years ago
Marcus Da Coregio c4d23f2b49 Use MvcRequestMatcher by default if Spring MVC is present 3 years ago
Josh Cummings 380a6a2564
Polish SecurityContextHolderStrategy Usage 3 years ago
Josh Cummings f16d47c7b5
Polish DefaultHttpSecurityExpressionHandler 3 years ago
Josh Cummings 4ddec07d0e
Add default AuthorizationManager 3 years ago
Steve Riesenberg ee9449dbfe
Fix tests for deferred CSRF tokens 3 years ago
Steve Riesenberg 521cdfd738
Use correct servlet imports 3 years ago
Steve Riesenberg dce1c30522
Add support for BREACH 3 years ago
Steve Riesenberg 475b3bb6bb
Add deferred CsrfTokenRepository.loadDeferredToken 3 years ago
Daniel Garnier-Moiroux 0e215a21ad
Add X-Xss-Protection headerValue to XML config 3 years ago
Marcus Da Coregio 039e0328e1 Simplify Java Configuration RequestMatcher Usage 3 years ago
Marcus Da Coregio 64a19de4dc Deprecate HPKP security header 3 years ago
Rob Winch 4479cefade Default Require Explicit Session Management = true 3 years ago
Daniel Garnier-Moiroux 93250013e4
Make X-Xss-Protection configurable through ServerHttpSecurity 3 years ago
Steve Riesenberg e0e6467d9b
Remove UsernamePasswordAuthenticationToken check 3 years ago