Seongguk Jeong
d8eadd2207
Replace deprecated method
...
Replace HttpMethod.resolve() to HttpMethod.valueOf()
2 years ago
Marcus Da Coregio
64e2a2ff8b
Apply updated Code Style
...
Closes gh-13881
2 years ago
Marcus Da Coregio
18e88366d2
Resolve The matchingRequestParameterName From The Query String
...
Prior to this commit, the ServletRequest#getParameter method was used in order to verify if the matchingRequestParameterName was present in the request. That method has some side effects like interfering in the execution of the ServletRequest#getInputStream and ServletRequest#getReader method when the request is an HTTP POST (if those methods are invoked after getParameter, or vice-versa, the content won't be available). This commit makes that we only use the query string to check for the parameter, avoiding draining the request's input stream.
Closes gh-13731
2 years ago
Marcus Da Coregio
ce012a4661
CookieRequestCache Should Preserve Request Locale
...
Closes gh-13792
2 years ago
Marcus Da Coregio
96d1763fc4
WWW-Authenticate header should not be added twice
...
Closes gh-13737
2 years ago
Josh Cummings
a4d8c62ad7
withHttpOnlyCookie defaults to false
...
Closes gh-13659
2 years ago
Seongguk Jeong
bcd4dcc15c
Refactor equals method
...
Using the accessor method for fields instead of directly access
2 years ago
Seongguk Jeong
ea19f82b8a
Using pattern matching for instanceof
2 years ago
Marcus Da Coregio
7813a9ba26
Use default PathPatternParser instance
3 years ago
Josh Cummings
40d61743b9
Replace Existing Continue Parameter
...
Closes gh-13438
3 years ago
Marcus Da Coregio
863aa5f65f
Fix Documented Default Value for AuthorizationFilter properties
...
Closes gh-13456
3 years ago
Christoph Zuleger
06e58e4c34
Update JavaDoc of BasicAuthenticationFilter
...
Remove deprecated hint to use Digest Auth in favor of Basic Auth.
3 years ago
Marcus Da Coregio
a53cbb838b
Polish
...
Issue gh-13155
3 years ago
joerg-richter-5234
8287289bcb
Fix XContentTypeOptionsServerHttpHeadersWriter
...
set constant value to X-Content-Type-Options
Closes gh-13155
3 years ago
Josh Cummings
4c5bf3bdf5
Polish
...
Use StringUtils#hasText
PR gh-13179
3 years ago
Dennis Frommknecht
af233a2a00
Use consistent list of micrometer tags in web observation handler
...
The tag `spring.security.reached.filter.name` is only set if a
filter-name is available, otherwise the tag is omitted entirely. This
leads to issues with metric-exporters that don't support dynamic tags,
but rather expect tag-names of a metric to be always the same. The most
prominent example is the Prometheus-exporter.
Instead of omitting the tag if no filer-name is set, a none-value is
applied instead, making the tag-list consistent in all cases
Closes gh-13179
3 years ago
Josh Cummings
e033e347b4
Remove Redundant Close
...
Closes gh-12787
3 years ago
Josh Cummings
5d903b5b71
Enforce start happens-before stop
...
Closes gh-13133
3 years ago
Steve Riesenberg
07b884a2cb
Add Set-Cookie header value for XSRF-TOKEN
...
This commit fixes an issue where using HttpServletResponse#setHeader
causes previous header values to be overwritten.
Closes gh-13075
3 years ago
Marcus Da Coregio
2d52fb8e4b
Clear Repository on Logout
3 years ago
Marcus Da Coregio
01d1e20dc3
Deprecate shouldFilterAllDispatcherTypes
...
Closes gh-12138
3 years ago
Josh Cummings
02345b97ff
Polish Observation Event Names
...
Issue gh-12811
3 years ago
bvn13
59ba7f5388
Shorten Observation Event Names
...
Closes gh-12811
3 years ago
Christian Marck
442faccb5f
Avoid NPE in FilterInvocation
...
Handle unknown headers in dummy request wrapper.
Closes gh-12998
3 years ago
Josh Cummings
6db2b0dcd0
Align Filter Chain Observability Lineage
...
Closes gh-12849
3 years ago
Christian Schuster
6791f3208e
Add factory class for RequestMatcher composition
...
Closes gh-12751
3 years ago
Marcus Da Coregio
8d664bc4c2
DelegatingSecurityContextRepository should call loadContext
...
Closes gh-12314
3 years ago
Josh Cummings
3fbb64db96
Fix javax package
3 years ago
twosom
3d7e22a4e9
Add test to SimpleUrlAuthenticationSuccessHandlerTests
3 years ago
twosom
abd51f7b63
Polished DefaultLoginPageGeneratingFilterTests Validation
...
Closes gh-12694
3 years ago
Josh Cummings
9bba1a1c6b
Propagate Variables in And and OrRequestMatcher
...
Closes gh-12847
3 years ago
Marcus Da Coregio
84cca81edf
Use HttpSessionSecurityContextRepository by default in SwitchUserFilter
...
Closes gh-12834
3 years ago
Josh Cummings
c06e604278
Address Observability Thread Safety
...
Closes gh-12829
3 years ago
twosom
28d353d731
Extract errorMessage from generateLoginPageHtml
3 years ago
twosom
ae23e3f5f4
Use instanceof pattern matching in initAuthFilter
3 years ago
twosom
99eacf2f0b
Change private static method to private methods
3 years ago
Josh Cummings
8ca726f4fa
Specify query string
...
Issue gh-12665
3 years ago
Josh Cummings
0d4c619648
Include continue in query string
...
Closes gh-12665
3 years ago
twosom
073dab3bf6
Refactor SavedCookie for Cookie's deprecated method
...
Closes gh-12454
3 years ago
twosom
a855b33535
fix typo in RememberMeAuthenticationFilter
3 years ago
Steve Riesenberg
c306df9b46
Add XorCsrfChannelInterceptor
...
Issue gh-12378
3 years ago
Josh Cummings
879770a0f6
Polish AbstractAuthenticationTargetUrlHandler
...
Issue gh-12344
3 years ago
Dayan Kodippily
6b8a778da8
Rework determineTargetUrl for Readability
...
Closes gh-12344
3 years ago
Dayan Kodippily
58e948a781
Test AbstractAuthenticationTargetUrlRequestHandler
...
Issue gh-12344
3 years ago
Steve Riesenberg
62b58d2c92
Polish gh-12530
3 years ago
Onur Kagan Ozcan
c77c76e722
Relax final modifiers on AbstractRememberMeServices methods
...
Closes gh-12145
3 years ago
Josh Cummings
4d2dab9b6b
Lookup Parent Observation
...
Closes gh-12524
3 years ago
Steve Riesenberg
4e80338a9b
Polish gh-12466
3 years ago
Wellington Domiciano
2c8854bb7f
Adjusts setRequestHandler javadoc in CsrfFilter
...
Adjusts setRequestHandler method javadoc in CsrfFilter class to reflect
changes in 6.0.
In 6.0, the default CsrfTokenRequestHandler changed to
XorCsrfTokenRequestAttributeHandler, however, the javadoc for the
setRequestHandler method still said it was
CsrfTokenRequestAttributeHandler.
This change adjusts the information to make it more accurate, because,
although XorCsrfTokenRequestAttributeHandler is a subclass of
CsrfTokenRequestAttributeHandler, the behavior is quite different.
Closes gh-12464
3 years ago
Marcus Da Coregio
ffdb397830
Save the SecurityContext when switching user
...
Closes gh-12504
3 years ago