Spring Buildmaster
98abd29c9f
Release version 3.2.6.RELEASE
11 years ago
Rob Winch
050407564c
SEC-2871: Polish README.adoc
11 years ago
Rob Winch
1374898cd8
SEC-2879: Add Test
11 years ago
Michael Cramer
d5ed97eba6
SEC-2879: JdbcTokenRepositoryImpl updateToken should use lastUsed arg
11 years ago
Marcin Mielnicki
8f29c2cc36
SEC-2878: Clean imports in UsernamePasswordAuthenticationFilter
11 years ago
Eugene Wolfson
99d503f0a9
SEC-2877: Fix doc typo in index.adoc
...
Replace "a`" with "a `"
11 years ago
Romain Fromi
6c185f649b
SEC-2876: HttpSecurityBuilder addFilterAfter javadoc before->after
11 years ago
izeye
58be282f70
SEC-2875: Fix typo in hellomvc guide
11 years ago
Rob Winch
2df05ee2c3
SEC-1915: Polish
...
* Restore default search filter to remain passive
* Check the search filter in setSearchFilter
* Add additional tests
11 years ago
Mateusz Rasiński
72bc6bf539
SEC-1915: Custom ActiveDirectory search filter
...
Currently the search filter used when retrieving user details is hard coded.
New property in ActiveDirectoryLdapAuthenticationProvider:
- searchFilter - the LDAP search filter to use when searching for authorities,
default to search using 'userPrincipalName' (current) OR 'sAMAccountName'
11 years ago
Rob Winch
1b26d03479
SEC-2832: Fix config tests
11 years ago
Rob Winch
dfaebfa63b
SEC-2872: CsrfAuthenticationStrategy Delay Saving CsrfToken
11 years ago
Rob Winch
f794272bac
SEC-2832: Add Tests
11 years ago
Stillglade
aa0a5b96ab
SEC-2832: Update request attributes with new CsrfToken
11 years ago
Rob Winch
27c7cd150b
SEC-2871: Polish README.adoc
11 years ago
shaehnel
b3d108fa44
SEC-2871: readme.txt->README.adoc
11 years ago
Rob Winch
975e4ec019
SEC-2078: AbstractPreAuthenticatedProcessingFilter requriesAuthentication support for non-String Principals
...
Previously, if the Principal returned by getPreAuthenticatedPrincipal was not a String,
it prevented requiresAuthentication from detecting when the Principal was the same.
This caused the need to authenticate the user for every request even when the Principal
did not change.
Now requiresAuthentication will check to see if the result of
getPreAuthenticatedPrincipal is equal to the current Authentication.getPrincipal().
11 years ago
Rob Winch
74f8534b17
SEC-2791: AbstractRememberMeServices sets the version
...
If the maxAge < 1 then the version must be 1 otherwise browsers ignore
the value.
11 years ago
Rob Winch
478a9650aa
SEC-2831: Regex/AntPath RequestMatcher handle invalid HTTP method
11 years ago
Rob Winch
b79ba12502
SEC-2777: Fix <header> attributes in doc
11 years ago
Rob Winch
72de17d79a
SEC-2822: Make EnableGlobalAuthenticationAutowiredConfigurer static Bean
...
This ensures that EnableGlobalAuthenticationAutowiredConfigurer is actually
used in newer versions of Spring. See SPR-12646
11 years ago
Rob Winch
e27200a255
SEC-2815: Delay looking up AuthenticationConfiguration
11 years ago
Rob Winch
c3f72f7b79
Merge pull request #160 from ractive/3.2.x
...
SEC-2812: Fix german translations in 3.2.x
11 years ago
james
b42cb9e3e1
SEC-2812: Fix german translations in 3.2.x
11 years ago
Rob Winch
b40088b73d
Merge pull request #155 from wilkinsona/powermock-upgrade
...
Upgrade to PowerMock 1.6.1
11 years ago
Andy Wilkinson
4116596a6c
Upgrade to PowerMock 1.6.1
...
The Platform would like to move to JUnit 4.12 but cannot do so at the
moment as Spring Security uses a version of PowerMock which is
incompatible with JUnit 4.12. This commit updates Spring Security to use
PowerMock 1.6.1 with is compatible with JUnit 4.12.
11 years ago
Christopher Pelloux
9de369c25f
SEC-2800 Documentation typo in class name
11 years ago
Rob Winch
bf2d2d4597
SEC-2773: Add Test for static delegatingApplicationListener
11 years ago
Oliver Gierke
c05f27af6c
SEC-2773: Prevent premature container initialization in WebSecurityConfiguration.
...
Changed the bean definition method for the DelegatingApplicationListener
to be static to avoid the need to instantiate the configuration class which
caused further premature initializations to satisfy the dependencies
expressed in setFilterChainProxySecurityConfigurer(…).
11 years ago
Rob Winch
cdac4d990b
SEC-2747: Remove spring-core dependency from spring-security-crypto
11 years ago
Rob Winch
db66843e0b
SEC-2749: CsrfConfigurer.requireCsrfProtectionMatcher correct null check
11 years ago
Rob Winch
c36cc88ac4
SEC-2150: Support class level annotations on Spring Data Repositories
11 years ago
Rob Winch
7d82349b1e
SEC-2150: Add tests to verify JSR-250 Spec behavior
11 years ago
Rob Winch
b6ab9c85e9
SEC-2682: DelegatingSecurityContextRunnable/Callable delegate toString()
11 years ago
Rob Winch
29a8da4aa6
SEC-2574: Fix Bundlr
11 years ago
Rob Winch
b71989ecde
SEC-2574: JavaConfig default SessionRegistry processes SessionDestroyedEvents
11 years ago
Rob Winch
eeef91498a
SEC-2674: Documentation refers to httpStrictTransportSecurity() instead of hsts()
11 years ago
Spring Buildmaster
91bf099b01
Next development version
12 years ago
Rob Winch
137589325d
SEC-2547: Update to cas-client-core-3.3.3
12 years ago
Rob Winch
0a184a8d79
SEC-2697: Fix logging of Spring Version Check
12 years ago
Rob Winch
2cb99f0791
SEC-2688: CAS Proxy Ticket Authentication uses Service for host & port
12 years ago
Rob Winch
d85a0a20bc
SEC-2595: @EnableGlobalMethodSecurity AspectJ tweaks for Spring 3.2.x
12 years ago
Rob Winch
0a45d3170c
SEC-2595: @EnableGlobalMethodSecurity AspectJ fixes
12 years ago
Rob Winch
89c5c56849
SEC-2599: HttpSessionEventPublisher get required ApplicationContext
...
In order to get better error messages (avoid NullPointerException) the
HttpSessionEventPublisher now gets the required ApplicationContext which
throws an IllegalStateException with a good error message.
12 years ago
Rob Winch
47acf17323
SEC-2588: Javadoc fix channelSecurity->requiresChannel
12 years ago
Rob Winch
52c585aef1
SEC-2665: Fix samples/ldap-jc link in reference
12 years ago
Rob Winch
89d80ed5c9
SEC-2683: Correct spelling of assignamble in AuthenticationPrincipalResolver Exception
12 years ago
Mirko Zeibig
85a37bdc02
SEC-2656: Fix <frame-options> with whitelist strategy
12 years ago
Rob Winch
fb1f2dc888
Next development version ldap/pom.xml
12 years ago
Rob Winch
d5842f949b
SEC-2657: Test for multi dynamic ports for LDAP Java Config
12 years ago