Commit Graph

  • 3ee8733261 SEC-879: Added required BeanPostProcessor to set SessionRegistry is set on namespace registered AbstractProcessingFilter and SessionFixationProtectionFilter when using custom ConcurrentSessionController http://jira.springframework.org/browse/SEC-879. Luke Taylor 2008-06-20 22:08:05 +00:00
  • d5ee89bb7c Correct typo in error message. Luke Taylor 2008-06-19 15:21:03 +00:00
  • ff5bfccdba SEC-892: Linked use of create-session='never' in namespace to corresponding properties in ExceptionTranslationFilter and AbstractProcessingFilter Luke Taylor 2008-06-19 13:46:45 +00:00
  • 5b089aea16 SEC-852 Scott Battaglia 2008-06-18 17:34:14 +00:00
  • d7f194df78 SEC-886 Scott Battaglia 2008-06-18 17:22:20 +00:00
  • c56d524bd9 SEC-887: Added setter method for account status checker. Luke Taylor 2008-06-18 12:00:45 +00:00
  • af5f193ec1 SEC-890: Corrected use of dataSource property name in RememberMeBDP. Luke Taylor 2008-06-18 10:35:30 +00:00
  • 7d79ae5424 SEC-880: Fix incorrect index value. Luke Taylor 2008-06-13 10:58:01 +00:00
  • 3e5b65bd85 Updated version names etc in petclinic tutorial Luke Taylor 2008-06-12 12:23:25 +00:00
  • 64b5fa0131 Added OWASP and Spring Framework links to site template Luke Taylor 2008-06-11 17:46:43 +00:00
  • fe929bf9b9 Added reference to OWASP site to preface of ref manual Luke Taylor 2008-06-11 17:35:27 +00:00
  • 8a2581c939 Experimental integration test module Luke Taylor 2008-06-10 22:17:44 +00:00
  • 55caab3bbc Added spring-jdbc dep back in core-tiger (since it's optional in core) hence not transient) Luke Taylor 2008-06-10 22:00:27 +00:00
  • 269865ca65 Removed spring deps from core-tiger pom as they are transiently available anyway Luke Taylor 2008-06-10 21:41:20 +00:00
  • 32b8009bee SEC-875: Removed duplicated parameters from SavedRequestWrapper.getParameterValues() Luke Taylor 2008-06-09 23:33:36 +00:00
  • 3b775d29d3 SEC-870: Polish messages file contribution Luke Taylor 2008-06-08 22:09:47 +00:00
  • 0401dddda8 SEC-868: Added example siteminder config Luke Taylor 2008-06-08 18:53:22 +00:00
  • 358f284f42 SEC-760: Correct bug where more than one concurrent JaasAuthenticationProvider used. Ben Alex 2008-06-06 06:13:14 +00:00
  • b403216494 SEC-838: Make fields in AbstractAclProvider protected to facilitate subclass reuse. Ben Alex 2008-06-06 03:01:51 +00:00
  • 371769740a SEC-831: Improve support for Postges, which requires "AS" for table aliasing, together with stored procedures for sequence allocation. Ben Alex 2008-06-06 02:55:53 +00:00
  • e38d5dfd87 SEC-813: Allow custom Permission classes to be used. Ben Alex 2008-06-06 02:37:19 +00:00
  • ff5666ae83 SEC-819: Properly support integer (and other numeric) identifiers. Ben Alex 2008-06-06 01:05:46 +00:00
  • de897ad1ac SEC-867: Remove superfluous <property /> entry. Ben Alex 2008-06-05 22:51:47 +00:00
  • ff785a829f [maven-release-plugin] prepare for next development iteration Luke Taylor 2008-06-03 16:07:20 +00:00
  • db1d8604a6 [maven-release-plugin] prepare release spring-security-parent-2.0.2 Luke Taylor 2008-06-03 16:05:40 +00:00
  • f762920239 Typo Luke Taylor 2008-06-03 15:49:21 +00:00
  • 70826f1202 Shorten faq question Luke Taylor 2008-06-03 15:48:30 +00:00
  • ea25299bd0 Removed sandbox from build because of site generation problems Luke Taylor 2008-06-03 15:37:41 +00:00
  • d784d854cd Corrected log file name. Luke Taylor 2008-06-03 14:57:40 +00:00
  • 9308284bd4 SEC-864: Removed duplicate OpenID provider. Luke Taylor 2008-06-03 14:53:43 +00:00
  • c34eb497c8 Correct captcha module dependency Luke Taylor 2008-06-03 14:11:30 +00:00
  • de250d2073 Add sandbox code to build for 2.0.2 release Luke Taylor 2008-06-03 13:41:38 +00:00
  • 8df56c8ac5 Test log4j properties file for core-tiger module Luke Taylor 2008-06-03 13:21:23 +00:00
  • 192aa25b60 Addtional sample app files Luke Taylor 2008-06-03 13:04:50 +00:00
  • d95a5597c8 Bug-testing changes to heavyduty sample Luke Taylor 2008-06-03 12:58:13 +00:00
  • 122e1c47ed Changed rnc filename prior to 2.0.2 release Luke Taylor 2008-06-01 19:34:50 +00:00
  • 64ab7e534c Spelling corrections in Javadoc. Luke Taylor 2008-06-01 17:26:27 +00:00
  • ab6d29d927 SEC-862: Make logoutSuccessUrl accessible to sub-classes. Luke Taylor 2008-06-01 16:15:09 +00:00
  • 2a510f3539 Added question on login with multiple fields to faq Luke Taylor 2008-06-01 15:25:39 +00:00
  • 7c0f8b9756 Corrected typo in docbook. Luke Taylor 2008-05-30 20:48:05 +00:00
  • 1d9d7eb9a7 Removed accidental commit of SavedRequest clearing code in TargetUrlResolverImpl Luke Taylor 2008-05-30 17:53:09 +00:00
  • 0cfcc0e9f1 Tidying Javadoc Luke Taylor 2008-05-30 17:51:23 +00:00
  • 373f7b648b Corrected outdated filter name in Javadoc Luke Taylor 2008-05-30 17:49:03 +00:00
  • a5cae70949 SEC-800: Removed references to outdated method configuration classes. Luke Taylor 2008-05-30 16:35:09 +00:00
  • ecd2cc6da7 Added some Assert calls to setters and improved comments. Luke Taylor 2008-05-30 15:29:51 +00:00
  • f228d013d8 SEC-861: Change default value of justUseSavedRequestOnGet to false Luke Taylor 2008-05-30 15:09:51 +00:00
  • 4de4bb8e87 SEC-860: Added setter for authenticationDetailsSource to AbstractRememberMeServices Luke Taylor 2008-05-30 14:29:32 +00:00
  • f8cded10ee Typo. Luke Taylor 2008-05-30 11:20:16 +00:00
  • c031588975 SEC-606: Added support for customizable credentials character set. Luke Taylor 2008-05-29 18:00:15 +00:00
  • 36a192b70f SEC-858: Replaced integer properties in schema with strings to allow use of placeholders. Luke Taylor 2008-05-29 16:13:14 +00:00
  • 980a72f9a0 Removed TODO (done). Luke Taylor 2008-05-29 15:54:50 +00:00
  • 517a7f117a SEC-857: Make request wrapper getParameterValues() consistent with getParameterMap() etc. Luke Taylor 2008-05-29 15:49:43 +00:00
  • 244579faf4 OPEN - issue SEC-856: GroupManager JdbcUserDetailsManager implementation: addGroupAuthority() method doesn't work. http://jira.springframework.org/browse/SEC-856. Refactored class to remove the JDBC-related inner classes. Luke Taylor 2008-05-28 16:25:28 +00:00
  • 87ba871605 Minor doc updates Luke Taylor 2008-05-28 13:38:33 +00:00
  • d63536cc0d SEC-821: Added support for eternal session registry and concurrent session controller to the 2.0.2 namespace. Luke Taylor 2008-05-27 13:14:21 +00:00
  • 8b5bbe3800 SEC-830: Changed SavedRequestAwareWrapper to make wrapped request parameters take precedence over saved request ones. Luke Taylor 2008-05-25 22:57:03 +00:00
  • cf4072c517 Context file improvements (based on sts suggestions) Luke Taylor 2008-05-25 20:57:07 +00:00
  • 4b45e5d7c2 Fixed OSGi version numbers in ranges [x,y] by adding a property pom.version.osgi Luke Taylor 2008-05-25 20:55:17 +00:00
  • 45c3084502 SEC-836: Made LDAP namespace elements use subtree group searching by default. Luke Taylor 2008-05-23 23:57:01 +00:00
  • 871e529840 SEC-850: custom-authentication-provider Registering Separate Bean Definitions in App Context and Providers List http://jira.springframework.org/browse/SEC-850. Added extra test. Luke Taylor 2008-05-23 23:32:57 +00:00
  • d1005e4cfb SEC-850: custom-authentication-provider Registering Separate Bean Definitions in App Context and Providers List http://jira.springframework.org/browse/SEC-850. Changed bean decorator to add a bean reference to the ProviderManager rather than a bean definition. Luke Taylor 2008-05-23 23:25:09 +00:00
  • 9ce0270226 Fixed typo in test name Luke Taylor 2008-05-23 22:57:30 +00:00
  • 7603ce2f97 SEC-848: Remove all Spring LDAP dependecy loading from namespace parsers http://jira.springframework.org/browse/SEC-848. Replaced class references with class names. Luke Taylor 2008-05-23 21:30:57 +00:00
  • 859e99edf4 SEC-851: Fix port number in LDAP sample. Luke Taylor 2008-05-23 21:24:48 +00:00
  • 25ba269db0 SEC-835: use setContentType on response for J2EE 1.3 compatibility. Luke Taylor 2008-05-23 20:55:10 +00:00
  • 11b448c0e0 SEC-847: Updated the xsl file to inline openid-login and other elements Luke Taylor 2008-05-23 16:29:44 +00:00
  • 08c5fe8925 Fixed autoboxing issue Luke Taylor 2008-05-22 12:19:00 +00:00
  • fbe3ca48f4 SEC-823, SEC-843: Allow setting of custom RememberMeServices and token validity periodon remember-me namespace element Luke Taylor 2008-05-21 16:03:05 +00:00
  • 3e33b8a880 Update InMemoryXmlApplicationContext to use 2.0.2 schema Luke Taylor 2008-05-20 22:46:37 +00:00
  • b60c578b25 SEC-844: Support for SHA-256 hashing. Luke Taylor 2008-05-20 22:45:02 +00:00
  • 03981ab6a0 SEC-844: Added sec-256 to namespace schema Luke Taylor 2008-05-20 22:32:03 +00:00
  • e9adbd4d62 SEC-844, SEC-843, SEC-823: Added support for sha-256, custom remember-me services and setting of remember me token validity period to namespace schema. Also added 2.0.2 XSD file Luke Taylor 2008-05-20 19:48:32 +00:00
  • 29d31b72d0 SEC-837: Add special character filtering to LDAP search filters Luke Taylor 2008-05-20 19:25:37 +00:00
  • 3fb1f59fde SEC-837: Add special character filtering to LDAP search filterscore/src/test/java/org/springframework/security/ldap Luke Taylor 2008-05-20 19:22:49 +00:00
  • 219d2e8962 Corrected link Luke Taylor 2008-05-20 10:57:17 +00:00
  • ff215e6750 Minor doc fixes Luke Taylor 2008-05-20 10:54:29 +00:00
  • 6ae81d553b SEC-842: Minor doc fixes Luke Taylor 2008-05-20 10:48:59 +00:00
  • 5af53da106 Improved doc for'filters' attribute Luke Taylor 2008-05-18 11:09:50 +00:00
  • 2329dadf48 Removed jalopy parameter comments Luke Taylor 2008-05-15 17:58:15 +00:00
  • fb5eefeea5 SEC-740: Finished preauth chapter Luke Taylor 2008-05-15 17:00:45 +00:00
  • f269373442 IDE-791: Remove explicit Spring LDAP class dependencies from LdapServerBDP. Luke Taylor 2008-05-15 14:33:42 +00:00
  • 4f6b4e4bfd Make sample login pages use c:out for data output Luke Taylor 2008-05-15 12:48:13 +00:00
  • 8b2c0468ff OPEN - issue SEC-834: Session fixation attack protection will cause problems with URL rewriting http://jira.springframework.org/browse/SEC-834. Modified HttpSecurityBDP to add session-fixation parameters to openId and form-login filters. Also added sessionRegistry property to AbstractProcessingFilter so that it doesn't conflict with concurrent session control. Luke Taylor 2008-05-15 01:34:14 +00:00
  • d17a2da9e0 SEC-834: Session fixation attack protection will cause problems with URL rewriting http://jira.springframework.org/browse/SEC-834. Changed position of SessionFixationProtectionFilter and modified it to make a decision about whether authentication has taken place prior to calling doFilter(). Previously it did this on the return through the filter chain, which caused the problem described in this issue. Luke Taylor 2008-05-15 00:26:27 +00:00
  • 7f38c656ca SEC-820: Expand regular expression used in hierarchical roles. Luke Taylor 2008-05-14 22:59:33 +00:00
  • 6493df13f8 SEC-803: Removed use of websphere SubjectHelper class. Luke Taylor 2008-05-14 22:51:39 +00:00
  • d4defb10fe SEC-833: Fixed login-failure-url in contacts sample app. Luke Taylor 2008-05-14 22:41:13 +00:00
  • 59543af4fb SEC-826: Support for JPA PersistenceContext annotation broken http://jira.springframework.org/browse/SEC-826 Moved all injection post-processing to BeanPostProcessors (and deleted bean factory post-processor) to prevent early instantiation problems. Beas should now all be instantiated before the injection takes place. Luke Taylor 2008-05-14 16:41:52 +00:00
  • 332f8fe5a1 SEC-624: Minor updates to docs Luke Taylor 2008-05-13 17:16:19 +00:00
  • 7a8eec11da SEC-765: Brief outline of preauth sample Luke Taylor 2008-05-13 17:14:45 +00:00
  • ff61644219 SEC-740: More on preauth Luke Taylor 2008-05-13 17:13:47 +00:00
  • 1fee538c7e Fixed typo in setter method (uses of). Luke Taylor 2008-05-13 15:32:30 +00:00
  • ae2470127c Fixed typo in setter method "seAttributePrefix" Luke Taylor 2008-05-13 13:51:49 +00:00
  • 2a4d859812 SEC-829: Minor doc fix Luke Taylor 2008-05-13 10:18:09 +00:00
  • 15b893f9ae SEC-809: OpenIDProcessingFilter updated to set authentication details (to make compatible with concurrent session control). Luke Taylor 2008-05-12 20:05:24 +00:00
  • de886e36fa SEC-624: Expanded general info on obtaining samples and added pointers to ldap and cas versions Luke Taylor 2008-05-10 17:21:18 +00:00
  • ad9a667b75 SEC-624: Inserted sub-sections for key class definitions so they appear in toc Luke Taylor 2008-05-10 17:19:46 +00:00
  • f70701d55a SEC-624: Added section on 'getting the source' for reference from samples chapter Luke Taylor 2008-05-10 17:18:29 +00:00
  • e1b226ee57 Added 2.0.2 namespace file Luke Taylor 2008-05-10 17:16:46 +00:00
  • af0153d833 Extended intro to Authentication part to include pointers to tech overview and namespace config Luke Taylor 2008-05-10 17:10:49 +00:00