Rob Winch
8c4ff64db0
Release Spring Security 5.1.0.RC2
...
Fixes: gh-5823
7 years ago
Rob Winch
26e577b0fa
UnauthenticatedServerOAuth2AuthorizedClientRepository->UnAuthenticatedServerOAuth2AuthorizedClientRepository
...
Issue: gh-5817
7 years ago
Rob Winch
11ea92ef1c
Add UnauthenticatedServerOAuth2AuthorizedClientRepository
...
Fixes: gh-5817
7 years ago
Rob Winch
96d85ad2b5
Polish HttpsRedirectWebFilter
...
Issue: gh-5749
7 years ago
Josh Cummings
2c982a4168
Reactive Redirect to Https
...
This introduces the capability to configure Reactive Spring Security
to upgrade requests to HTTPS
Fixes: gh-5749
7 years ago
Johnny Lim
f164f2f869
Polish FilterComparator
...
Extracts STEP incrementing into a separate helper class
7 years ago
Joe Grandja
d4576a2502
Update to Spring 5.1.0.RC3
...
Fixes gh-5798
7 years ago
Joe Grandja
c4ded37030
Update to jsp-api:2.3.3
...
Fixes gh-5795
7 years ago
Joe Grandja
f6a24afb1b
Update to selenium-support:3.14.0
...
Fixes gh-5794
7 years ago
Joe Grandja
5ace871ef1
Update to nimbus-jose-jwt:6.0.2
...
Fixes gh-5793
7 years ago
Joe Grandja
31634e25be
Update to oauth2-oidc-sdk:6.0
...
Fixes gh-5792
7 years ago
Joe Grandja
bf2484e6fa
Update to selenium-java:3.14.0
...
Fixes gh-5791
7 years ago
Joe Grandja
0e5cbd36e6
Update to jaxb-api:2.4.0-b180830.0359
...
Fixes gh-5788
7 years ago
Joe Grandja
5728108149
Update to javax.persistence:2.2.1
...
Fixes gh-5786
7 years ago
Joe Grandja
54484639bb
Update to htmlunit-driver:2.32.1
...
Fixes gh-5784
7 years ago
Joe Grandja
451fd50189
Update to hibernate-entitymanager:5.3.6.Final
...
Fixes gh-5782
7 years ago
Joe Grandja
7a24e7d648
Update to mockito-core:2.21.0
...
Fixes gh-5781
7 years ago
Joe Grandja
05b8457b5f
Update to assertj-core:3.11.1
...
Fixes gh-5780
7 years ago
Josh Cummings
21e62683ab
Polish Commit on Reactive Http Basic Test
7 years ago
Tim Koopman
6df4dfe47b
Reactive HttpBasic Support For Coloned Passwords
...
This makes so that reactive httpBasic supports passwords containing
one or more colons.
7 years ago
Josh Cummings
9e0f171d47
Jwt Claim Mapping
...
This introduces a hook for users to customize standard Jwt Claim
values in cases where the JWT issuer isn't spec compliant or where the
user needs to add or remove claims.
Fixes: gh-5223
7 years ago
Rob Winch
2495025845
authcodegrant samples->oauth2webclient samples
...
The authcodegrant samples were initially meant to be very simple
demonstration of authorization code flow. However, it has become
obvious since then that the real intent of the demo is how to use
the WebClient with OAuth (there is no other reason to do authorization
code flow unless you use the token to make a request).
The samples have been migrated to oauth2webclient and oauth2webclient-webflux
respectively. They have been improved:
* The sample demonstrates usage with annotations, webclient directly, form login
oauth2Login, and public APIs
* The samples externalize the endpoint that is requested in the sample
making it easier to try other endpoints
* The UI no longer relies on a data structure for the result of the
endpoint also making it easier to try other endpoints
Issue: gh-4921
7 years ago
Rob Winch
438d2911fb
OAuth2AuthorizedClientResolver
...
Extract out a private API for shared code between the argument resolver
and WebClient support. This makes it easier to make changes in both
locations. Later we will extract this out so it is not a copy/paste
effort.
Issue: gh-4921
7 years ago
Rob Winch
23726abb1e
ServerOAuth2AuthorizedClientExchangeFilterFunction default ServerWebExchange
...
Leverage ServerWebExchange established by ServerWebExchangeReactorContextWebFilter
Issue: gh-4921
7 years ago
Rob Winch
ac78258847
ServerOAuth2AuthorizedClientExchangeFilterFunction defaultOAuth2AuthorizedClient
...
Defaults to use the OAuth2AuthenticationToken to resolve the authorized client
Issue: gh-4921
7 years ago
Rob Winch
158b8aa6d5
ServerOAuth2AuthorizedClientExchangeFilterFunction clientRegistrationId
...
Issue: gh-4921
7 years ago
Rob Winch
28537fa3b6
WebClientReactiveClientCredentialsTokenResponseClient
...
Fixes: gh-5607
7 years ago
Rob Winch
89f2874bff
ServerOAuth2AuthorizedClientExchangeFilterFunction clientRegistrationId
...
You can now provide the clientRegistrationId and
ServerOAuth2AuthorizedClientExchangeFilterFunction will look up the authorized client automatically.
Issue: gh-4921
7 years ago
Rob Winch
5bcbb1c40f
ServerOAuth2AuthorizedClientExchangeFilterFunction uses ServerOAuth2AuthorizedClientRepository
...
Issue: gh-4921
7 years ago
Rob Winch
07b6699fd9
ServerWebExchangeReactorContextWebFilter
...
Fixes: gh-5779
7 years ago
Josh Cummings
65c81ce952
Make JwtReactiveAuthenticationManager final
7 years ago
Joe Grandja
057587ef29
ClientRegistration contains Provider Configuration Metadata
...
Fixes gh-5540
7 years ago
Sola
c60fcf263e
provide test for custom principal extractor config
...
Signed-off-by: Sola <dev@sola.love>
7 years ago
Sola
2980f96b55
Allow PrincipalExtractor to be customized.
...
Signed-off-by: Sola <dev@sola.love>
7 years ago
Josh Cummings
932ea245fb
AuthenticationManager for OAuth2ResourceServerSpec
...
This makes the AuthenticationManager used by the OAuth2 Resource
Server configurable, focusing at this point on the Jwt use case.
Fixes: gh-5750
7 years ago
Joe Grandja
dfd572a4d2
Polish
7 years ago
Joe Grandja
3b480a3a05
Provide RestOperations in CustomUserTypesOAuth2UserService
...
Fixes gh-5602
7 years ago
Joe Grandja
4a8c95a3e8
Provide RestOperations in DefaultOAuth2UserService
...
Fixes gh-5600
7 years ago
Josh Cummings
25d1f49d84
Remove Resource Server's Session Policy Config
...
Resource Server doesn't need to set the session policy for the
application to STATELESS since it can rely on the
SessionManagementFilter ignoring token's annotated with @Transient ,
which a JwtAuthenticationToken is.
Fixes: gh-5759
7 years ago
Johnny Lim
5141dacd95
Upgrade to Gradle Wrapper 4.10
...
Closes gh-5748
7 years ago
Rob Winch
5dd55d4936
Ensure NamingException.resolvedObj is Serializable
...
Fixes: gh-5378
7 years ago
Josh Cummings
8510e9a285
Reactive Resource Server insufficient_scope
...
This introduces an implementation of ServerAccessDeniedHandler that is
compliant with the OAuth 2.0 spec for insufficent_scope errors.
Fixes: gh-5705
8 years ago
Josh Cummings
1c74706232
Delegating ServerAccessDeniedHandler by exchange
...
Fixes: gh-5747
8 years ago
Joe Grandja
8e615d0fee
Re-factor DefaultClientCredentialsTokenResponseClient
...
Fixes gh-5735
8 years ago
Rob Winch
713e1e3356
BearerTokenServerAuthenticationEntryPoint waits for subscriber
...
Fixes: gh-5742
8 years ago
Vedran Pavic
362c2ef1f2
Force snapshot repo in snapshot stage build
8 years ago
Joe Grandja
229b69dd35
Add DefaultAuthorizationCodeTokenResponseClient
...
Fixes gh-5547
8 years ago
Vedran Pavic
f7cb53e9bd
Upgrade spring-build-conventions to 0.0.18.RELEASE
8 years ago
Vedran Pavic
cb0ba58b58
Fix WhitespaceAfterCheck Checkstyle check
8 years ago
Jason Zhekov
439538477a
Add missing space in namespace.adoc
8 years ago