910 Commits (5.3.12.RELEASE)

Author SHA1 Message Date
Josh Cummings 9481122e02 Restructure SwitchUserFilter Logs 4 years ago
Marcus Hert da Coregio 02285708eb Adjust createNewSessionIfAllowed to prevent NPE 5 years ago
Craig Andrews a85ce9c91f
Add guard around logger.debug statement 5 years ago
佚名 22d7043d01
Add null check in CsrfFilter and CsrfWebFilter 5 years ago
Rob Winch 419839d05c Optimize HttpSessionSecurityContextRepository 5 years ago
Rob Winch 38e9e8ca52 Optimize HttpSessionSecurityContextRepository 5 years ago
Josh Cummings 10946e8153
Polish Tests 5 years ago
happier233 3cb98ebed0
Configure CurrentSecurityContextArgumentResolver BeanResolver 5 years ago
Rob Winch e6d6b39767 Constant Time Comparison for CSRF tokens 5 years ago
Rob Winch b08075a721 Fix CsrfWebFilter error message when expected CSRF not found 5 years ago
Tomoki Tsubaki e44471331b
Create the CSRF token on the bounded elactic scheduler 5 years ago
Rob Winch 070706d948 LoginPageGeneratingWebFilter honors context path 6 years ago
Joe Grandja 38c1e3ffa8 OAuth2LoginAuthenticationWebFilter should handle OAuth2AuthorizationException 6 years ago
Eleftheria Stein 2ebbb6f80a Mock request with non-standard HTTP method in test 6 years ago
cbornet b6efd5ba76 Create the CSRF token on the bounded elactic scheduler 6 years ago
Artyom Tarynin 9e665388d2 Update AntPathRequestMatcher.java 6 years ago
Rob Winch 06a02ed4bb Fix non-standard HTTP method for CsrfWebFilter 6 years ago
Rob Winch 566c25aa10 Fix example in javadoc of FilterChainProxy 6 years ago
Rob Winch 0e6e2b2a21 Fix HttpServlet3RequestFactory Logout Handlers 6 years ago
Josh Cummings 034c23d46c
SwitchUserFilter Defaults to POST 6 years ago
Zeeshan Adnan dfa78804a8 Fix exception for empty basic auth header token 6 years ago
AmitB 2ce9eef95e Fix typo in AntPathRequestMatcher contructor comment 6 years ago
Joe Grandja 82cd203791 Remove unnecessary mocking 6 years ago
Josh Cummings bae50ecc05
AbstractSecurityWebApplicationInitializerTests groovy->java 6 years ago
Josh Cummings cb9fd09150
Change AuthenticationWebFilter's constructor 6 years ago
Peter Keller e62fb755e8 Set charset of BasicAuthenticationFilter converter 6 years ago
Onur Kağan Özcan 1f6381d970 Set secure on cookie when logging out 6 years ago
Rob Winch ffccec953f Fix HttpHeaderWriterWebFilterTests 6 years ago
Onur Kağan Özcan 2015f392ef Set secure when cancelling remember-me cookie 6 years ago
Rob Winch a8331ba7ed CompositeServerHttpHeadersWriter Executes Sequentially 6 years ago
David Herberth 64e063d948 switches web authentication principal resolver to use reactive context 6 years ago
Rob Winch 8e53c3f269 DelegatingServerAuthenticationSuccessHandler Executes Sequentially 6 years ago
Rob Winch 73babc3314 DelegatingServerLogoutHandler Executes Sequentially 6 years ago
Joe Grandja 4d9cee116c Display general error message when WebFlux oauth2Login() fails 6 years ago
Filip Hrisafov 796859333f Log full failed authentication exception in BasicAuthenticationFilter 6 years ago
Josh Cummings 5f17032ffd Restore Removed Throws Clauses 6 years ago
Rob Winch 635f7e1edd CsrfWebFilter supports multipart/form-data 6 years ago
Filip Hrisafov b9f122230b Align javadoc of continueFilterChainOnUnsuccessfulAuthentication with actual behaviour 6 years ago
Michel Palourdio d26f40f062 DefaultRedirectStrategy should redirect to root if the context-relative URL does not contain the context-path. 6 years ago
Tadaya Tsuyukubo 62c7de03c3 Add RequestMatcher to AbstractPreAuthenticatedProcessingFilter 6 years ago
Eleftheria Stein 264daec697 Test context relative URL with multiple schemes 6 years ago
Josh Cummings b764af6b9b
CookieServerCsrfTokenRepositoryTests Leading Dot 6 years ago
Josh Cummings 7949dd492a
Move DelegatingServerAuthenticationSuccessHandlerTests 6 years ago
Josh Cummings 5f905232cb
Polish CurrentSecurityContextArgumentResolvers 6 years ago
Onur Kagan Ozcan 034b5e9e93 Introduce LogoutSuccessEvent 6 years ago
Josh Cummings 7576dc44d7
AuthenticationFilter Session Fixation Protection 6 years ago
Josh Cummings 496a2cdc60
Make AuthenticationFilter methods private 6 years ago
Josh Cummings aa12748c9b Add Request-level CSRF Skip 6 years ago
Eleftheria Stein 9f0986a093 Fix javadoc typo for invalid session strategy 6 years ago
Filip Hanik e9a44bc0ce HttpSecurity.saml2login() - MVP Core Code 6 years ago