4069 Commits (3.0.7.RELEASE)
 

Author SHA1 Message Date
Luke Taylor 714ee3e960 Set version to 3.0.7.RELEASE. 15 years ago
Luke Taylor ee74c4ced2 SEC-1803: Add check in AbstractAuthenticationTargetUrlRequestHandler for null targetUrlParameter before attempting to read it from the request. Prevents NPE when targetUrlParameter is not set. 15 years ago
Luke Taylor 102027a44c SEC-1804: Updated Javadoc wrt immutability of User class. 15 years ago
Luke Taylor 799a43d72e SEC-1804: Update InMemoryDaoImpl to use User class directly and create a copy. Otherwise credentials are cleared on cached user instances. 15 years ago
Luke Taylor 3dc4158f7d Set version to 3.0.7.CI-SNAPSHOT 15 years ago
Luke Taylor 62f70f17ff Set project release version to 3.0.6.RELEASE 15 years ago
Luke Taylor 4b0fbe1606 Remove session timeout check in tutorial sample. 15 years ago
Luke Taylor a8bce41876 SEC-1795: Fix possible NPEs in AclImpl.equals() 15 years ago
Luke Taylor cea1f4499f SEC-1686: Upgrade to Spring 3.0.6 15 years ago
Luke Taylor c19a5ffd73 SEC-1796: Check for annotated annotations at class/interface level. Previously only the specific security annotation was checked for. By delegating to Spring's AnnotationUtils, custom annotations carrying the security annotation are also detected. 15 years ago
Luke Taylor 594ee9515e Taglib test fixes to take latest SFW changes into account. 15 years ago
Luke Taylor a087e828a6 SEC-1790: Disable use of spring-security-redirect by default for SimpleUrlLogoutSuccesshandler. 15 years ago
Luke Taylor 5238ba0e26 SEC-1790: Reject redirect locations containing CR or LF. 15 years ago
Luke Taylor 887e3361d2 SEC-1750: Make sure RunAs replacement is constrained to the SecurityContext of the current thread. 15 years ago
Luke Taylor a24570ae06 SEC-1744: Do not trust authorities contained in the authentication request in JaasAuthenticationProvider. 15 years ago
Luke Taylor ba719dc0e1 SEC-1741: Modify ContextPropagatingRemoteInvocation to pass a simple combination of principal/credentials as Strings, rather than serializing the whole SecurityContext object from the client. 15 years ago
Luke Taylor 28e70db8f2 SEC-1742: Deprecate use of extraInformation field in AuthenticationException, making it transient and removing any sensitive data in UserDetails objects which are stored in it. 15 years ago
Rob Winch 84031c6001 SEC-1792: Fixed NullPointerException in RunAsUserToken#toString() 15 years ago
Luke Taylor ca2af8bc59 SEC-1770: Call refreshLastRequest on the session registry rather than the SessionInformation object to make sure it works with alternative SessionRegistry implementations. 15 years ago
Luke Taylor 6f59805ef3 SEC-1782: Javadoc correction for LdapAuthenticationProvider. 15 years ago
Rob Winch f359bed596 SEC-1777: Corrected log in HttpSessionSecurityContextRepository to reference itself instead of HttpSessionContextIntegrationFilter 15 years ago
Florian Fankhauser 0f1ae574ab SEC-1776: Corrected typo in manual 15 years ago
Luke Taylor cb7a94af88 SEC-1768: Use AopProxyUtils.ultimateTargetClass to cater for situation where security interceptor is applied to a proxy. 15 years ago
Luke Taylor 9b8d2719a6 SEC-1686: Up required minimum version to 3.0.6 in version check. 15 years ago
Luke Taylor 73b67da3a8 SEC-1762: Fix input value assertion check for targetUrlParameter. 15 years ago
Luke Taylor b5546d1d29 SEC-1764: Remove use of Java 6 method Arrays.copyOfRange. 15 years ago
Luke Taylor 70ca0d1a39 SEC-1764: Ensure password encoders use UTF-8 charset when creating strings from byte arrays. 15 years ago
Luke Taylor 7a5a062cd0 SEC-1764: Backport Utf8 encoder to 3.0.x 15 years ago
Luke Taylor 977da0da1f SEC-1733: Support explicit zero netmask correctly. 15 years ago
Luke Taylor dfbc938e99 Added note in namespace docs on mismatch between using filters="none" and other attributes. 15 years ago
Rob Winch d5f1f6cbff SEC-1757: Updated tutorial sample to state that listing of accounts is allowed by anyone and to display accounts for the different types of access to posting to Accounts 15 years ago
Luke Taylor a2cdbab50c SEC-1747: Upgrade to Spring LDAP 1.3.1 15 years ago
Luke Taylor 1833b234a5 SEC-1722: Correct javadoc 15 years ago
Luke Taylor 6c97fccc91 SEC-1700: Allow for case where JAAS config is not a simple file, but may be a jar resource, for example. 15 years ago
Luke Taylor 2888f2b86f SEC-1720: Avoid bean-creation side-effects in ContextSourceSettingPostProcessor. 15 years ago
Luke Taylor 04d42211b1 SEC-1705: Make sure a single OpenIDAuthenticationFilter bean is created by the namespace. Likewise for UsernamePasswordAuthenticationFilter. 15 years ago
Rob Winch 6a87a5f1a1 SEC-1703: Updated namespace for intercept-url 15 years ago
Rob Winch f6b21880a2 SEC-1703: Updated cas custom-filter@ref to match example bean id and custom-filter@position to be CAS_FILTER 15 years ago
Luke Taylor 198d5d0482 SEC-1701: Trim claimed identity parameter value before submitting to OpenID4Java. 15 years ago
Rob Winch acee3e2593 SEC-1698: Update documentation to use correct package for RequestHeaderAuthenticationFilter 15 years ago
Luke Taylor b87dabe1ac SEC-1683: Corrected typo 15 years ago
Luke Taylor f509193604 Update Base64 implementation to include fixes (using diff) from the original up to version 2.3.7. 15 years ago
Luke Taylor 11a091f051 SEC-1680: Revert accidental updates to 3.0.x namespace appendix. 15 years ago
Luke Taylor 8e48658efb SEC-1675: Added missing "body-content" elements to taglib descriptor. 15 years ago
Rob Winch afd556412e SEC-1672: Provide error message when ambiguous configuration of intercept-url contains attributes filters=none and (access or requires-channel) 15 years ago
Luke Taylor 187a530760 SEC-1670: Take account of JNDI CompositeName escaping in value of SearchResult.getName() when performing a search for a user entry in SpringSecurityLdapTemplate. 15 years ago
Rob Winch 1b6587a5d4 SEC-1666: Use constant time comparison for sensitive data. 15 years ago
Rob Winch ece824fca2 SEC-1592: Updated CasAuthenticationFilter so that it does not continue FilterChain when handling proxy requests. 15 years ago
Luke Taylor e3644e2d27 SEC-1661: Use a DistinguishedName to wrap the search base to avoid the need for JNDI escaping. 15 years ago
Rob Winch b3943ac268 SEC-1545: Removed unused i18n keys, changed keys to follow naming conventions, found missing keys based upon old keys, sorted keys, any unknown keys are entered as a comment with the English value. 15 years ago