Rafael Dominguez
e60e17109c
Update to Gradle 4.10.2
...
Fixes gh-6106
7 years ago
Josh Cummings
2a8233d035
Remove PowerMock from oauth2-core and oauth2-jose
...
Issue: gh-6025
7 years ago
Josh Cummings
9ee291e659
AesBytesEncryptorTests Check Key Strength
...
Fixes: gh-6121
7 years ago
Satish Sharma
7232dabd48
Update to oauth2-oidc-sdk:6.2
...
Fixes: gh-6101
7 years ago
Josh Cummings
3a43ed8f1c
Register NullRequestCache When Disabled
...
Fixes: gh-6102
7 years ago
Josh Cummings
80e13bad41
Remove PowerMock from oauth2-client
...
Issue: gh-6025
7 years ago
Josh Cummings
39933b10ff
Add scopes method to TestOAuth2AccessTokens
...
Issue: gh-6025
7 years ago
dperezcabrera
f6414e9a52
Make InMemory*ClientRegistrationRepository Consistent
...
The previous builders with the list argument were inconsistent with their
respective builders of var args.
7 years ago
Rafael Dominguez
e1d68e4f6b
WebClientReactiveClientCredentialsTokenResponseClient.getTokenResponse expects 2xx http status code
...
This ensures that token response is only extracted when ClientResponse has a successful status
Fixes: gh-6089
7 years ago
Josh Cummings
f30fcdda6b
RequestCacheConfigurerTests groovy->java
...
Issue: gh-4939
7 years ago
Josh Cummings
686393ed5c
ExceptionHandlingConfigurerTests groovy->java
...
Issue: gh-4939
7 years ago
Josh Cummings
1ea73e7d8e
Jwt Decoder Local Key Configuration
...
Adds support for configuring Resource Server DSL with a local public
key.
Fixes: gh-5131
7 years ago
Rafael Dominguez
75a2c2b729
OAuth2AccessTokenResponseBodyExtractor supports Object values
...
This commit ensures the token response is parsed correctly if the values are not a String.
Fixes: gh-6087
7 years ago
Daniel Bustamante Ospina
808fbfa161
Update webflux-form sample to use Built in CSRF Support
...
Remove the CsrfControllerAdvice class and update dependencies to add
org.thymeleaf.extras:thymeleaf-extras-springsecurity5
Issue: gh-6061
7 years ago
Josh Cummings
d28e32b000
NimbusJwtDecoder Builder
...
A Builder to simply common construction patterns for NimbusJwtDecoder
Issue: gh-6010
7 years ago
Josh Cummings
fbcf48cea0
Low-level Nimbus Jwt Decoder
...
Introduces a JwtDecoder which takes a raw Nimbus JWTProcessor
configuration.
Fixes: gh-5648
7 years ago
Karl Goffin
db5e54266c
#3912 lazyBean method respects @Primary annotation
7 years ago
Dongmin Shin
b2c2f84f00
Fix Typo in Reference Docs
...
Fixes gh-6076
7 years ago
Rafael Dominguez
ac026e23fe
Updated Spring Boot version from 2.1.0.M4 to 2.1.0.RELEASE
7 years ago
Krzysztof Szmytkowski
b5455b0bec
Make AesByesEncryptor public
...
Fixes: gh-5099
7 years ago
Josh Cummings
13de580632
AesBytesEncryptorTests
...
Issue: gh-5099
7 years ago
Johnny Lim
95c824cb2a
Upgrade to neko-htmlunit 2.33
7 years ago
Josh Cummings
ae74f22e30
Reactive Jwt Claim Set Converter Support
...
Exposes setClaimSetConverter on NimbusReactiveJwtDecoder, lining it up
with the same support on NimbusJwtDecoder.
Fixes: gh-6015
7 years ago
Gunnar Hillert
11b6b63364
Docs: Fix Maven Property example `spring-security.version`
7 years ago
Josh Cummings
2769b7ffb0
Leave Issuer As String - Documentation
...
Update documentation that indicated the iss claim is proactively
coerced into a URL.
Issue: gh-6073
7 years ago
Josh Cummings
19649db9ce
Leave Issuer As String
...
Since StringOrURI is a valid issuer, MappedJwtClaimSetConverter and
JwtIssuerValidator no longer assume it.
Issue: gh-6073
7 years ago
Josh Cummings
c70b65c5df
Favor URL.toExternalForm
...
Converts URLs to Strings before comparing them. Uses toString(),
which delegates to toExternalForm().
Fixes: gh-6073
7 years ago
Josh Cummings
a32d19ec7d
Polish NimbusReactiveJwtDecoderTests
...
Issue: gh-5650
7 years ago
Josh Cummings
8eedb3919e
Policy OAuth2ResourceServerSpecTests
...
Issue: gh-6052
7 years ago
Josh Cummings
dca3645850
Update to spring-build-conventions:0.0.22.RELEASE
...
Fixes: gh-6064
7 years ago
dperezcabrera
898d005a53
InMemoryUserDetailsManager.updatePassword case-insenstive
...
Previously updatePassword was case sensitive which was
inconsistent with the rest of the class.
This commit updates updatePassword to be case insensitive.
Fixes: gh-6039
7 years ago
Erik van Paassen
3a6582d2a6
Fix csrf:token-repository-ref XSD documentation
...
The documentation of the token-repository-ref attribute of the csrf
element in the schema has been updated to make clear the default
repository is lazy. Targets versions 4.2, 5.0 and 5.1.
Fixes gh-6037
7 years ago
Josh Cummings
9a13f9acde
Custom Bearer Token Error Handling Support
...
Users can specify a custom access denied handler and authentication
entry point for reactive resource servers.
Fixes: gh-6052
7 years ago
Josh Cummings
78e27ca17f
Update Reactive Resource Server Docs
...
Resource Server documentation for both Servlet and Reactive now have a
similar feel and offer deeper exposure to common use cases.
Fixes: gh-6054
7 years ago
Josh Cummings
8a475e39be
Write Security Headers Before Servlet Include
...
HeaderWriterFilter wraps request dispatcher so it can write security
headers before the include occurs.
Fixes: gh-5499
7 years ago
Paul Wheeler
ccc4e1c876
Made AclClassIdUtils genuinely package level by injecting the conversionService instead of AclClassIdUtils
...
Fixes gh-4814
7 years ago
Paul Wheeler
2c362456fd
AclClassIdUtils should be public
...
Fixes gh-4814
7 years ago
Josh Cummings
75e7e099ab
MiscHttpConfigTests groovy->java
...
Issue: gh-4939
7 years ago
Josh Cummings
7d3302f52b
Polish Test Name
...
So that it adheres to methodNameWhenConditionThenVerification naming
convention.
Issue: gh-3743
7 years ago
Karl Goffin
50d26c9d28
Polish Logging and Tests
...
Removing debug statements which would have prematurely terminated the
stream, changing to AssertJ, and adding another test.
Issue: gh-3743
7 years ago
Karl Goffin
92e68a589a
PostFilter Support for Streams
...
Users can return a Stream from a @PostFilter-annotated method.
Fixes: gh-3743
7 years ago
Josh Cummings
e1c7dd6480
Add JDK 11 to Jenkins
...
Fixes: gh-5860
7 years ago
Josh Cummings
42b111fba6
JDK 11 Compatibility
...
Upgraded dependencies and removed a test in the Java Config LDAP
sample which is arguably an integration test since it starts up an
LDAP container. This test also isn't JDK 11 compatible and the
remaining integration tests in the sample cover the same material.
Issue: gh-5860
7 years ago
Joe Grandja
a96893a42a
Remove charset from Accept header in UserInfo request
...
Fixes gh-6017
7 years ago
Bob Maertz
52be2839ca
Migraged unit test from groovy to java
...
Moved AbstractConfigAttributeRequestMatcherRegistryTests.groovy to AbstractConfigAttributeRequestMatcherRegistryTests.java
gh-4939
7 years ago
Joe Grandja
8ef65ce5c5
Set AuthenticationEventPublisher on each AuthenticationManagerBuilder
...
Fixes gh-6009
7 years ago
Joe Grandja
7a94931514
Polish javadoc
7 years ago
Bob Maertz
551ea66ce3
Migrated unit test TldTests.groovy to TldTests.java
...
Moved unit test TldTests#testTldVersionIsCorrect from groovy to java.
gh-4939
7 years ago
Rob Winch
f56f55dc8e
Fix BCrypt Checkstyle
...
Issue: gh-3320
7 years ago
linfeng
388a7b62b9
Add BCrypt Revision Support
...
Fixes: gh-3320
7 years ago