Commit Graph

  • 23ef7dac48 SEC-2009: Support ./gradlew eclipse Rob Winch 2012-07-19 17:42:36 -05:00
  • c9facdd993 SEC-2013: Add space to log of AbstractAuthenticationProcessingFilter Rob Winch 2012-07-19 16:13:12 -05:00
  • 24c3bdfd90 SEC-2013: Add space to log of AbstractAuthenticationProcessingFilter Rob Winch 2012-07-19 16:13:12 -05:00
  • 1710f32a08 SEC-2011: Moved SessionRegistry documentation of SessionRegistry#onAuthentication Rob Winch 2012-07-19 11:14:49 -05:00
  • b868daaa8c SEC-2011: Remove reference to SessionRegistry from SessionFixationProtectionStrategy javadoc Rob Winch 2012-07-19 10:20:40 -05:00
  • 095dcb3a74 SEC-2010: Include missing <value> tag in Hierarchical Roles section of the reference Rob Winch 2012-07-19 10:18:12 -05:00
  • aa4ec9a508 Cleaned up warnings in JdbcTokenRepositoryImpl and JdbcTokenRepositoryImplTests Rob Winch 2012-07-18 16:35:28 -05:00
  • 340534dadb SEC-1964: Handle missing series in JdbcTokenRepositoryImpl Rob Winch 2012-07-18 16:17:26 -05:00
  • 7f9938c8e2 Organize imports on RememberMeConfigTests Rob Winch 2012-07-18 14:40:22 -05:00
  • c7c41ced84 Added test to verify LogoutHandlers added to LogoutFilter Rob Winch 2012-07-18 14:39:15 -05:00
  • 3ce06333c5 SEC-1850: Namespace adds all LogoutHandlers to ConcurrentSessionFilter Rob Winch 2012-07-18 14:36:24 -05:00
  • 06638db289 SEC-1909: Namespace configuration no longer uses deprecated API's Rob Winch 2012-07-17 14:07:16 -05:00
  • b196d70f99 SEC-1905: Added para tag to the digest encoded password footnote Rob Winch 2012-07-11 13:12:57 -05:00
  • bfd09f7603 SEC-1905: Added footnote to password encoding for digest authentication Rob Winch 2012-07-11 13:00:06 -05:00
  • 40ccbedefd SEC-1988: Add contributor guide link to readme.txt Rob Winch 2012-07-10 22:27:19 -05:00
  • 42b72bcbc4 SEC-1980: Prevent parser warning when URL's in configuration start with # Rob Winch 2012-07-10 14:24:42 -05:00
  • b28e3a0b2f SEC-1976: include *.aj files in sourceJar Rob Winch 2012-07-09 18:13:07 -05:00
  • 262ee099df SEC-1994: explicit sourceCompatibility and targetCompatibility of 1.5 in Gradle build Rob Winch 2012-07-08 15:55:21 -05:00
  • 3e4da4f60f Updated to next snapshot version Rob Winch 2012-07-06 11:28:21 -05:00
  • f46a5bab40 Set to 3.1.1 Release Rob Winch 2012-07-06 09:15:13 -05:00
  • 638e92a3f7 SEC-1992: Updated Spring version to 3.0.7 Rob Winch 2012-07-06 10:24:54 -05:00
  • d14150c2e1 SEC-1906: Fix EmmaPlugin for Gradle 1.0 Rob Winch 2012-07-05 22:57:16 -05:00
  • a6bded86c2 SEC-1990: Polishing code cleanup on BCrypt Rob Winch 2012-07-05 14:12:14 -05:00
  • 14a5135ac3 SEC-1990: Clean up jBCrypt and include its tests. Joseph Walton 2012-07-04 21:43:15 +10:00
  • fde9142d8d SEC-1907: Exclude crypto dependency in core module since classes are bundled in core Rob Winch 2012-07-05 13:56:47 -05:00
  • f2345fcb21 SEC-1981: Remove dependency on Locale for the build Rob Winch 2012-07-03 13:09:46 -05:00
  • a2452ab514 SEC-1906: Update to Gradle 1.0 Rob Winch 2012-06-29 12:59:22 -05:00
  • 2fba10ab61 Use powermock for testing servlet 3.0 functionality instead of distinct classpaths Rob Winch 2012-06-29 17:46:13 -05:00
  • 18230259b8 SEC-1985: Removed WebSecurityExpessionHandler from reference Rob Winch 2012-06-28 11:35:07 -05:00
  • f6902471fb SEC-1965: DefaultWebSecurityExpressionHandler is now passive from 3.0.x releases Rob Winch 2012-06-28 10:49:29 -05:00
  • b6ec700640 SEC-1968: AbstractPreAuthenticatedProcessingFilter clears SecurityContext on null principal change with invalidateSessionOnPrincipalChange = true Rob Winch 2012-06-27 15:12:48 -05:00
  • d2e6343295 SEC-1968: AbstractPreAuthenticatedProcessingFilter clears SecurityContext on null principal change with invalidateSessionOnPrincipalChange = true Rob Winch 2012-06-27 15:12:48 -05:00
  • 31338a7bdb SEC-1875: ConcurrentSessionControlStrategy no longer adds/removes the session to the SessionRegistry twice Rob Winch 2012-06-26 16:25:53 -05:00
  • e1068b84ea .gitignore src/*/java/META-INF/ Rob Winch 2012-06-26 16:27:22 -05:00
  • de3dfb5b3f SEC-1875: ConcurrentSessionControlStrategy no longer adds/removes the session to the SessionRegistry twice Rob Winch 2012-06-26 16:25:53 -05:00
  • 7714c5cd02 .gitignore bin and */src/*/java/META-INF Rob Winch 2012-06-15 14:54:48 -05:00
  • 5ed5590268 SEC-1970: Cleanup of pre authentication documentation Rob Winch 2012-06-15 14:51:50 -05:00
  • 954ba57cf2 SEC-1970: Cleanup of pre authentication documentation Rob Winch 2012-06-15 14:44:12 -05:00
  • 8b05d23832 SEC-1971: Allow injection of ExpressionParser in AbstractSecurityExpressionHandler Rob Winch 2012-06-14 16:43:20 -05:00
  • 5dd6b4a77a SEC-1865: Remove invalid OWASP link in TextEscapeUtils Rob Winch 2012-06-11 14:49:28 -05:00
  • 6584b65489 SEC-1898: Added test to demonstrate JdbcAclService#readAclById throws NotFoundException when the Acl is missing Rob Winch 2012-06-11 16:24:57 -05:00
  • 520b65e2e3 SEC-1865: Remove invalid OWASP link in TextEscapeUtils Rob Winch 2012-06-11 14:49:28 -05:00
  • a8b30ed6d9 .gitignore */src/*/java/META-INF Rob Winch 2012-06-11 14:48:24 -05:00
  • 254333ce82 SEC-1957: DefaultFilterChainValidator no longer casts to DefaultFilterInvocationSecurityMetadataSource Rob Winch 2012-04-29 15:59:24 -05:00
  • b626a63b85 Suppress warnings in AbstractAuthorizeTag and AuthorizeTagCustomGrantedAuthorityTests Rob Winch 2012-04-22 21:24:41 -05:00
  • d57f1d56d5 SEC-1900: AbstractAuthorizeTag now compares using getAuthority() Christian Hilmersson 2012-02-22 01:46:33 +01:00
  • c446697de3 Cleaned up warnings in FilterChainProxyTests Rob Winch 2012-04-11 17:23:07 -05:00
  • bb8f3bae7c SEC-1950: Defensively invoke SecurityContextHolder.clearContext() in FilterChainProxy Rob Winch 2012-04-11 17:22:19 -05:00
  • 5118e0b86e SEC-1943: Corrected namespace doc to state SecurityContextHolderAwareRequestFilter instead of SecurityContextHolderAwareFilter Rob Winch 2012-03-20 19:22:54 -05:00
  • ca741ab18f SEC-1943: Corrected namespace doc to state SecurityContextHolderAwareRequestFilter instead of SecurityContextHolderAwareFilter Rob Winch 2012-03-20 19:18:26 -05:00
  • 488efbc97e SEC-1901: Changed DebugFilter to no longer extend OncePerRequesetFilter so that the FilterChainProxy is invoked on forwards Rob Winch 2012-03-17 11:15:18 -05:00
  • a4322d70ba Merge pull request #5 from tburch/setUseSecureCookie-typo Rob Winch 2012-03-13 17:02:43 -07:00
  • f78c11650f SEC-1893: Namespace now register PortMapper with custom mappings for all components that use a PortMapper Rob Winch 2012-03-11 20:52:17 -05:00
  • 84141c4c76 SEC-1927: Corrected debug log in SessionManagementFilter to have a space between ID and the session and added guard to log statement Rob Winch 2012-03-11 18:29:56 -05:00
  • e7f47964ee fix typo in setUseSecureCookie method documentation Tristan Burch 2012-03-09 17:00:40 -07:00
  • 6bde4caa77 Merge pull request #4 from Abdull/master ltaylor 2012-02-28 14:15:53 -08:00
  • dec44811fc Gave correct role name Abdull 2012-02-28 14:41:14 +01:00
  • 0e413cedcb Gave correct role name Abdull 2012-02-28 14:39:30 +01:00
  • 3760d792ea SEC-1890: Add checks for validity of stored bcrypt hash Luke Taylor 2012-02-22 14:36:13 +00:00
  • 5d71d2a4fa SEC-1887: Add MethodSecurityOperations interface. Luke Taylor 2012-02-01 15:49:56 +00:00
  • 2434564d6c SEC-1904: Fixed LDAP object class name in docs. Luke Taylor 2012-02-01 14:37:32 +00:00
  • 538e75ce1b SEC-1903: Use a static CRLF Pattern in FirewalledResponse Luke Taylor 2012-02-01 13:21:16 +00:00
  • 0f9ee81df1 SEC-1887: Improve extensibility of expression-based security classes Andrei Stefan 2012-01-20 02:48:36 +02:00
  • b493afa18c SEC-1888: Improving the doc on (not) using multiple annotation types in the same class. Luke Taylor 2012-01-31 18:56:17 +00:00
  • f97463cdb5 Minor comment fixes Luke Taylor 2012-01-16 14:49:59 +00:00
  • 2d556c7b4f SEC-1885: Change SecurityDebugBeanFactoryPostProcessor to only interact with BeanDefinitions rather than instances to prevent premature instatiation of FilterChainProxy and its dependencies Rob Winch 2012-01-07 12:27:40 -06:00
  • 21f2991ab4 Call SecurityContextHolder.clearContext() in tear down of HttpSessionSecurityContextRepositoryTests Rob Winch 2011-12-30 14:30:17 -06:00
  • 3679227b11 SEC-1735: Do not remove SecurityContext from HttpSession when anonymous Authentication is saved if original SecurityContext was anonymous Rob Winch 2011-07-17 22:21:32 -05:00
  • 22225effcc Call SecurityContextHolder.clearContext() in tear down of HttpSessionSecurityContextRepositoryTests Rob Winch 2011-12-30 14:30:17 -06:00
  • 5d94cd5e13 SEC-1735: Do not remove SecurityContext from HttpSession when anonymous Authentication is saved if original SecurityContext was anonymous Rob Winch 2011-07-17 22:21:32 -05:00
  • 1f835fec43 SEC-1867: Perform null check on Authentication.getCredentials() prior to calling toString() Rob Winch 2011-12-30 13:59:04 -06:00
  • 25e17c1568 SEC-1881: Configure surefire to include **/*Test.class to avoid accidentally not running new tests that end in Test Rob Winch 2011-12-30 12:53:33 -06:00
  • 9847366d5e SEC-1881: Renamed **/*Test.java to **/*Tests.java since **/*Test.java are not included in surefire configuration Rob Winch 2011-12-28 17:56:44 -06:00
  • 7cb472f105 SEC-1880: Corrected error message when using both logout-success-url and success-handler-ref Rob Winch 2011-12-30 11:31:24 -06:00
  • 448a42916d SEC-1880: Corrected error message when using both logout-success-url and success-handler-ref Rob Winch 2011-12-30 11:31:24 -06:00
  • ea56a98883 SEC-1868: Remove error level logs from SecurityNamespaceHandler when the web classes are not available and not required Rob Winch 2011-12-29 22:26:08 -06:00
  • 6fe6e18939 SEC-1870: Updated HttpSessionDestroyedEvent to properly look for SecurityContexts as session attribute values instead of session attribute names Rob Winch 2011-12-29 15:41:21 -06:00
  • 044861eb20 Renamed **/*Spec.groovy to **/*Tests.groovy to better follow conventions Rob Winch 2011-12-28 17:09:51 -06:00
  • 8ca2927761 Renamed **/Test.java to **/Tests.java to better follow conventions Rob Winch 2011-12-28 17:05:46 -06:00
  • aabb16912f SEC-1878: DefaultFilterChainValidator properly handles AccessDecisionManager throwing exceptions other than AccessDeniedException Rob Winch 2011-12-27 14:28:49 -06:00
  • 863b36962b SEC-1878: Added test to ensure that DefaultFilterChainValidator can handle web expressions Rob Winch 2011-12-28 12:50:06 -06:00
  • bbfb3da9c7 Updated to maven-resources-plugin 2.4 Rob Winch 2011-12-28 15:19:48 -06:00
  • 00936c6b49 Switch to post release snapshot version. Luke Taylor 2011-12-05 23:44:55 +00:00
  • 9b423a7726 Set 3.1.0 release version. Luke Taylor 2011-12-05 23:42:39 +00:00
  • b1af3d00ee SEC-1857: Use Principal.getName() in ContextPropagatingRemoteInvocation Luke Taylor 2011-12-05 21:23:42 +00:00
  • 9fa6e78770 SEC-1857: Use Principal.getName() in ContextPropagatingRemoteInvocation Luke Taylor 2011-12-05 21:23:42 +00:00
  • 0de067ae63 SEC-1793: Added convenience constructor to DefaultSpringSecuritySontextSource Steffen Ryll 2011-07-04 11:10:49 +02:00
  • 999adbc6ee SEC-1827: If use-secure-cookie is set to false explicitly set useSecureCookie to false on AbstractRememberMeServices Rob Winch 2011-11-21 09:11:17 -06:00
  • 53483df1f5 SEC-1678: Added What's new section to reference Rob Winch 2011-11-18 11:23:42 -06:00
  • 041cb1dcc3 SEC-1858: Included the updates for logout-success-url documentation Rob Winch 2011-11-18 11:22:22 -06:00
  • 3dca70403d Suppress compiler warnings and minor javadoc fix for ProviderManager Rob Winch 2011-11-06 17:07:24 -06:00
  • ff495b698e SEC-1858: Removed methods for generating docbook for xsd Rob Winch 2011-11-11 09:00:53 -05:00
  • c8b847f1ed SEC-1858: Added integration tests to validate that the xsd is documented in the reference Rob Winch 2011-11-11 09:00:53 -05:00
  • f88b6f75ff SEC-1858: Overhall the namespace appendix of the reference to include missing elements and attributes Rob Winch 2011-11-11 09:00:53 -05:00
  • de397bc0ce SEC-1858: Updated xsd documentation to have documentation for all elements/attributes and added documentation of default values where appropriate Rob Winch 2011-11-11 09:00:53 -05:00
  • 8565116f20 SEC-1472: Add crypto wrappers for BCrypt Dave Syer 2011-11-02 17:58:06 +00:00
  • 944d762da9 Add eclipse generated meta-inf to ignores Dave Syer 2011-11-02 17:47:44 +00:00
  • 3b13a3fb25 SEC-1812: Replace assertion with warning message when overriding the global AuthenticationManager. Luke Taylor 2011-11-02 14:23:59 +00:00
  • daa7f3f64e SEC-1848: LDAP encode name when using user DN patterns in AbstractLdapAuthenticator. Luke Taylor 2011-11-01 13:28:56 +00:00
  • 8e1d407e3e SEC-1848: LDAP encode name when using user DN patterns in AbstractLdapAuthenticator. Luke Taylor 2011-11-01 13:28:56 +00:00