github-actions[bot]
4559d269e0
Release 5.6.7
3 years ago
Marcus Da Coregio
627809d2dc
Update org.springframework.data to 2021.1.6
...
Closes gh-11686
4 years ago
Marcus Da Coregio
4b1d7e9479
Update org.springframework to 5.3.22
...
Closes gh-11685
4 years ago
Marcus Da Coregio
d9980a4dfe
Update jsonassert to 1.5.1
...
Closes gh-11684
4 years ago
Marcus Da Coregio
8eb7e589eb
Update hibernate-entitymanager to 5.6.10.Final
...
Closes gh-11683
4 years ago
Marcus Da Coregio
0d7dce9d71
Update org.eclipse.jetty to 9.4.48.v20220622
...
Closes gh-11682
4 years ago
Marcus Da Coregio
da09788be9
Update io.projectreactor to 2020.0.22
...
Closes gh-11680
4 years ago
Marcus Da Coregio
ead587c597
Consistently handle RequestRejectedException if it is wrapped
...
Closes gh-11645
4 years ago
Steve Riesenberg
02459919cc
Skip workflows on forks of spring-security
4 years ago
Steve Riesenberg
57d212ddca
Use cache and user.name system property on Windows
4 years ago
Steve Riesenberg
539b17f6da
Only run prerequisites job if on upstream repo
4 years ago
Steve Riesenberg
37e1ad27fe
Simplify dependency graph
4 years ago
Steve Riesenberg
043fdd6f03
Use Spring Gradle Build Action
...
Closes gh-11630
4 years ago
Steve Riesenberg
3234e05085
Polish gh-11367
4 years ago
naveen
f957e3c051
Set permissions for GitHub actions
...
Restrict the GitHub token permissions only to the required ones; this
way, even if the attackers will succeed in compromising your workflow,
they won’t be able to do much.
- Included permissions for the action.
https://github.com/ossf/scorecard/blob/main/docs/checks.md#token-permissions
https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions
https://docs.github.com/en/actions/using-jobs/assigning-permissions-to-jobs
Keeping your GitHub Actions and workflows secure Part 1: Preventing pwn requests
https://securitylab.github.com/research/github-actions-preventing-pwn-requests/
Signed-off-by: naveen <172697+naveensrinivasan@users.noreply.github.com>
Closes gh-11367
4 years ago
Marcus Da Coregio
d66ad22652
Add Deprecated annotation to WebSecurity#securityInterceptor
...
Closes gh-11634
4 years ago
Rob Winch
7a860e1568
Fix Snapshot Sources/Javadoc
...
This commit merges a workaround to an issue in JFrog's Gradle plugin
which causes SNAPSHOT javadoc and sources to become out of sync and thus
prevents users from being able to download either.
Closes gh-10602
4 years ago
Desmond Silveira
0d3c3c676d
"Well-Know" should be "Well-Known"
4 years ago
Yuriy Savchenko
0f64d4c091
Add Kotlin example for WebTestClient setup docs
...
Closes gh-9998
4 years ago
Josh Cummings
56a6133b20
Merge Same-named Attribute Elements
...
Closes gh-11042
4 years ago
Steve Riesenberg
aaf20e7b61
Build only on branches
...
Issue gh-11480
4 years ago
Steve Riesenberg
148756076c
Backport release automation and github actions
...
Closes gh-11501
4 years ago
Steve Riesenberg
6f321a27c4
Fix inconsistency in hasProperty check
4 years ago
Steve Riesenberg
539443b4be
Add GitHubReleasePlugin with createGitHubRelease task
...
Issue gh-10456
Issue gh-10457
4 years ago
Josh Cummings
28424f8ae5
Correct input validation for 31 rounds
...
Closes gh-11470
4 years ago
Rob Winch
a7d21f1b34
Document sagan Release tasks require read:org scope
...
Closes gh-11423
4 years ago
Joe Grandja
d3a024786b
Next Development Version
4 years ago
Joe Grandja
fa4c5449e7
Release 5.6.6
4 years ago
Joe Grandja
2a3845a7ed
Update org.opensaml:opensaml-core4 to 4.1.1
...
Closes gh-11420
4 years ago
Joe Grandja
ff96a7b5ad
Update spring-ldap-core to 2.3.8.RELEASE
...
Closes gh-11419
4 years ago
Joe Grandja
c37ff42234
Update org.springframework.data to 2021.1.5
...
Closes gh-11418
4 years ago
Joe Grandja
0a00d84838
Update org.springframework to 5.3.21
...
Closes gh-11417
4 years ago
Joe Grandja
96c6751a1d
Update hibernate-entitymanager to 5.6.9.Final
...
Closes gh-11416
4 years ago
Joe Grandja
8ee9c32788
Update io.projectreactor to 2020.0.20
...
Closes gh-11414
4 years ago
Joe Grandja
7a5fb9eaf7
Update jackson-bom to 2.13.3
...
Closes gh-11411
4 years ago
Joe Grandja
8cbb972cef
Add dependency update exclusion for spring-javaformat-checkstyle
4 years ago
Josh Cummings
539a11d0a4
Encode postLogoutRedirectUri query params
...
Closes gh-11379
4 years ago
Zhivko Delchev
e97c5a533b
Reverse content type check
...
When MultipartFormData is enabled currently the CsrfWebFilter compares
the content-type header against MULTIPART_FORM_DATA MediaType which
leads to NullPointerExecption when there is no content-type header.
This commit reverse the check to compare the MULTIPART_FORM_DATA
MediaType against the content-type which contains null check and avoids
the exception.
closes gh-11204
Closes gh-11205
4 years ago
shirohoo
e0fa644b08
Fix typo in BasicLookupStrategy Javadoc
...
Closes gh-11336
4 years ago
Rob Winch
592db9180d
Enable BackportBot on 5.6.x
4 years ago
André Luis Gomes
aca3fc2412
Update opaque-token.adoc
...
Fixing yaml sample in Servlet and Reactive pages
4 years ago
Claudio Consolmagno
07f9afe057
Use 'md:' prefix in EntityDescriptor XML
...
Create the EntityDescriptor object with
EntityDescriptor.DEFAULT_ELEMENT_NAME instead of
EntityDescriptor.ELEMENT_QNAME. That ensures the EntityDescriptor tag
is marshalled to xml with the 'md:' prefix, consistent with all other
metadata tags.
Closes #11283
4 years ago
Josh Cummings
d7077b441a
Correct access(String) reference
...
Closes gh-11280
4 years ago
Josh Cummings
101f11ba94
Improve ContextConfiguration Docs
...
Point to updated Spring Reference
Issue gh-10934
4 years ago
Josh Cummings
18b903f6e3
Polish ExtendWith Docs
...
Use spring-framework-reference-url placeholder
Issue gh-10934
4 years ago
nor-ek
038266a94f
Update JUnit 5 annotations in documentation
...
- replace Before with BeforeEach
- replace RunWith with ExtendWith
Closes gh-10934
4 years ago
Evgeniy Cheban
cf559ab224
Some Security Expressions cause NPE when used within Query annotation
...
Added trustResolver, roleHierarchy, permissionEvaluator, defaultRolePrefix
fields to SecurityEvaluationContextExtension.
Closes gh-11196
Closes gh-11290
4 years ago
Juny Tse
649428b49a
Use Base64 encoder with no CRLF in output for SAML 2.0 messages
...
Closes gh-11262
4 years ago
Steve Riesenberg
0355e960d7
Next development version
4 years ago
Steve Riesenberg
fdad14af63
Release 5.6.5
4 years ago