Commit Graph

  • 07f820f1a6 Minor portlet-related changes suggested by John Lewis: Javadoc and default values of booleans. Luke Taylor 2008-03-31 10:10:13 +00:00
  • c9b6fe9555 OPEN - issue SEC-657: Create pre-authenticated processing filter which obtains username from request header http://jira.springframework.org/browse/SEC-657. Added filter and test class. Luke Taylor 2008-03-30 13:37:13 +00:00
  • b98c72056a SEC-728: Change use of String.getBytes() in password encoders to use UTF-8 Luke Taylor 2008-03-29 15:21:31 +00:00
  • 91a5a6c266 SEC-737: sandboxed captcha Luke Taylor 2008-03-29 14:49:40 +00:00
  • 52875e2c12 updated wtp version to 2.0 Luke Taylor 2008-03-29 14:48:31 +00:00
  • e74f826d6f Fixed broken sandbox build Luke Taylor 2008-03-29 14:45:31 +00:00
  • ea489baf6f SEC-730 Scott Battaglia 2008-03-28 18:25:02 +00:00
  • 1463b9769d SEC-629: authentication-provider doesn't support caching. http://jira.springframework.org/browse/SEC-629. Added support for cache-ref elements on jdbc-user-service and ldap-user-service Luke Taylor 2008-03-28 17:55:12 +00:00
  • db6fafaf56 SEC-629: authentication-provider doesn't support caching. Refactored MockUserCache class to top level Luke Taylor 2008-03-28 14:17:05 +00:00
  • 1490fe0b0a Various fine-tuning so people can see AspectJ expressions and a simple, minimal configuration. Ben Alex 2008-03-28 00:47:08 +00:00
  • 595a14dbd5 Sample should permit people to anonymously call all methods except post(Account). Ben Alex 2008-03-28 00:44:42 +00:00
  • 1fece47b49 SEC-691: Applied patch to allow setting of returned user attributes from LDAP search. Luke Taylor 2008-03-27 14:41:11 +00:00
  • 350a626587 SEC-477: Added preauthenticated websphere contribution. Luke Taylor 2008-03-27 14:25:17 +00:00
  • 608e8d3610 SEC-672. Forgot to set core-tiger packaging type to 'bundle' Luke Taylor 2008-03-26 21:54:48 +00:00
  • 584853bbcb Tidied imports. Luke Taylor 2008-03-26 21:49:26 +00:00
  • ef5b3e2f9c SEC-733: Changed names of <global-method-security> attributes as discussed with Ben and updated sample to reflect the changes. Also changed explicit instantiation of Jsr250 and Secured annotation MethodDefinitionSource beans in GlobalMethodSecurityBDP into bean definitions to make more tooling friendly. Luke Taylor 2008-03-26 21:48:24 +00:00
  • 9ea2408ac6 Fixed error in choosing main entry point (it's an alias not a bean name, so doesn't appear in the entry map - you have to get it direct from the bean factory). Luke Taylor 2008-03-26 17:34:42 +00:00
  • 071c91540c SEC-722: Added explicit login page to open-id element in openid sample. Luke Taylor 2008-03-26 17:01:54 +00:00
  • 743d72ca7b Added log4j support to tutorial app Luke Taylor 2008-03-26 15:27:09 +00:00
  • 1cd7865ed5 SEC-729: Removed version numbers and jstl declarations from sample parent pom Luke Taylor 2008-03-26 15:21:41 +00:00
  • 1b8a3c5673 SEC-689: Updated session fixation protection namespace support to set session registry on SessionFixationProtectionFilter. Luke Taylor 2008-03-26 14:51:16 +00:00
  • eeb14b3965 Changed filter order numbers to start at zero (makes them more readable in log compared with large negative numbers) Luke Taylor 2008-03-26 12:22:26 +00:00
  • 4681ff3d50 SEC-689: Fix 1.4 compatibility issue (overlooked autoboxing of boolean) Luke Taylor 2008-03-26 12:09:57 +00:00
  • 43b51ca64d SEC-689: Session Fixation protection should be available to all authentication mechanisms. http://jira.springframework.org/browse/SEC-689. Added support to namespace. Luke Taylor 2008-03-26 12:00:58 +00:00
  • 2af2f299cb SEC-689: Further tests, logging improvements. Luke Taylor 2008-03-26 00:00:56 +00:00
  • a29842a467 SEC-689: Tests for SessionFixationProtectionFilter Luke Taylor 2008-03-25 23:24:38 +00:00
  • 8f5bcb64a6 SEC-689: Session Fixation protection should be available to all authentication mechanisms. http://jira.springframework.org/browse/SEC-689. Added a general SessionFixationProtectionFilter which can be added to the filter stack to detect when a user has been authenticated and then migrate them to a new session. Also added support to <http/> namespace element. Luke Taylor 2008-03-25 22:32:26 +00:00
  • 83bcc6ad7c Removed loggers from subclasses of SpringSecurityFilter in favour of using base class logger. Luke Taylor 2008-03-25 14:51:34 +00:00
  • 0860333a3f SEC-733: AspectJ Pointcut Expression Parsing support. Ben Alex 2008-03-25 08:28:53 +00:00
  • f4eb15b08b SEC-428: Tests to prove proxy-target-class="true" works. Ben Alex 2008-03-24 23:10:01 +00:00
  • f8b5000d40 SEC-428: Make sure context is cleared before running test. Luke Taylor 2008-03-24 22:56:43 +00:00
  • 18fef571c3 Import cleaning. Luke Taylor 2008-03-24 22:44:42 +00:00
  • 028af06d61 SEC-428: Security interceptor does not work with schema based aop:config http://jira.springframework.org/browse/SEC-428. Fixed broken test method. Luke Taylor 2008-03-24 22:43:08 +00:00
  • a375d8e59e SEC-428: Added test Luke Taylor 2008-03-24 20:50:58 +00:00
  • 1dd5f42142 Adding svn keywords, correcting typos etc. Luke Taylor 2008-03-24 20:48:45 +00:00
  • ed645958fa per email with Ben and Luke removed cas-adapter and reworked cas module to just be the CAS client code. Scott Battaglia 2008-03-24 20:24:33 +00:00
  • 9a4977ebd1 SEC-99/428/429/563: Various refactoring of method security metadata support. Ben Alex 2008-03-24 09:40:13 +00:00
  • beba7221cf Update dependency versions and POM structure. Ben Alex 2008-03-24 09:16:12 +00:00
  • f67c7bcb38 Update dependency versions and POM structure Ben Alex 2008-03-24 09:06:46 +00:00
  • 6ab301981c Update dependency versions and POM structure. Ben Alex 2008-03-24 09:05:44 +00:00
  • 9a02b9862e Fixed preauth sample configuration to match recent changes in naming in core code. Luke Taylor 2008-03-23 23:03:28 +00:00
  • fe0e05a6c8 SEC-725: PasswordEncoderParser: <security:password-encoder> element does not pick up 'base64' attribute value http://jira.springframework.org/browse/SEC-725. Added fix as recommended in issue. Luke Taylor 2008-03-23 22:38:13 +00:00
  • b54e3978dc SEC-729: Organization of pom dependencies, particularly for servlet-api and jstl. Some other adjustments, removal of unrequired deps etc Luke Taylor 2008-03-23 00:31:32 +00:00
  • 3d0e0fcea5 fixed links in reference.xml Luke Taylor 2008-03-23 00:16:34 +00:00
  • 30a6abbe50 Tidied formatting of toString output for FilterBasedLdapUserSearch Luke Taylor 2008-03-22 21:40:54 +00:00
  • 162933155e Added implementation of GrantedAuthoritiesContainer to allow refactoring of duplication in various preauth details classes Luke Taylor 2008-03-22 19:29:13 +00:00
  • 2ea94e2cc9 Tidying imports etc Luke Taylor 2008-03-22 11:44:28 +00:00
  • 1d47945893 Added portlet and ldap samples to build Luke Taylor 2008-03-22 11:43:24 +00:00
  • 696e3c8034 Udated maven eclipse plugin version Luke Taylor 2008-03-22 11:42:52 +00:00
  • 69f2075872 SEC-722: Fix jstl versions in openID sample login page. Luke Taylor 2008-03-22 00:05:53 +00:00
  • 563dabda2f SEC-722: Add Open ID Namespace Support http://jira.springframework.org/browse/SEC-722. Added OpenIDProvider to bean registry and fixed login page generator to use correct URL for OpenID. Added user-service-ref to namespace element. Changed OpenID sample to use <openid-login />. Luke Taylor 2008-03-21 23:47:09 +00:00
  • b89dbc6060 Import cleaning Luke Taylor 2008-03-21 21:51:48 +00:00
  • 9871685ea3 SEC-722: Fixed problem with empty loginpage string (rather than null) preventing default login page filter from being added to the stack. Luke Taylor 2008-03-21 21:50:26 +00:00
  • b73736ffaf Updated example configuration in javadoc for LdapAuthenticationProvider. Luke Taylor 2008-03-21 17:12:22 +00:00
  • 037ccd5eaa Removed eclipse settings directory Luke Taylor 2008-03-21 13:53:36 +00:00
  • 16ea8faa0d SEC-727: Ensure SecurityConfig cannot be constructed unsafely; also update SecurityConfigTests to JUnit 4. Ben Alex 2008-03-21 02:15:47 +00:00
  • 119cc9ff04 Remove notice.txt due to mvn eclipse:eclipse issues with import from parent directory. Ben Alex 2008-03-21 01:22:31 +00:00
  • 5466fe0022 Added servlet api dep to captcha and cas Luke Taylor 2008-03-20 21:33:45 +00:00
  • acc22b2745 SEC-722: Add Open ID Namespace Support http://jira.springframework.org/browse/SEC-722. Added check for MAIN_ENTRY_POINT bean when resolving entry points. If this has been set during parsing it will be used. Luke Taylor 2008-03-20 20:11:34 +00:00
  • 815f04b6c3 SEC-722: Add Open ID Namespace Support http://jira.springframework.org/browse/SEC-722. Added element to namespace and modified form login parser to handle open id element. Also added openID support to login page generator. Luke Taylor 2008-03-20 20:05:11 +00:00
  • b62ad5b097 SEC-722: Changed openID filter to use its owen ordering value as it may be used together with form login. Luke Taylor 2008-03-20 19:55:32 +00:00
  • bbc5fea598 SEC-722: Add Open ID Namespace Support http://jira.springframework.org/browse/SEC-722. Added extra constants for OpenID support. Luke Taylor 2008-03-20 19:51:59 +00:00
  • d333655b0b Updated to commons logging 1.1.1 to get rid of servlet api dependency in their pom Luke Taylor 2008-03-20 19:43:55 +00:00
  • 56b967f935 Removed filer name duplication in rnc file. Luke Taylor 2008-03-20 15:10:21 +00:00
  • a65b5a9ed8 Corrected separators between http method strings in rnc file. Luke Taylor 2008-03-20 14:56:02 +00:00
  • 8f379768a8 SEC-720: Design for extension: PreAuthenticatedGrantedAuthoritiesUserDetailsService http://jira.springframework.org/browse/SEC-720. Added createUserDetails method to allow custom UserDetails object t be created. Luke Taylor 2008-03-19 18:29:38 +00:00
  • f3a6f768ba SEC-724: Create portlet sample http://jira.springframework.org/browse/SEC-724 Luke Taylor 2008-03-19 17:58:07 +00:00
  • 030550a88e Applied XSL transform to XSD file Luke Taylor 2008-03-19 17:04:39 +00:00
  • 2a0a041386 SEC-719: removed explicit toString() call to prevent NPE when userInfo is null Luke Taylor 2008-03-19 16:15:45 +00:00
  • b78bd3ed4f SEC-719: Change default value of useAuthTypeAsCredentials to true to prevent tests breaking Luke Taylor 2008-03-19 16:02:52 +00:00
  • 5de0f3b8f0 SEC-719: Refactor portlet code to make more use of core classes http://jira.springframework.org/browse/SEC-719. Rewrote provider as a preauthenticated provider. Luke Taylor 2008-03-19 15:45:42 +00:00
  • f8d855f1a2 SEC-716: Default (non-web) AuthenticationDetailsSource implementation. Luke Taylor 2008-03-18 18:45:38 +00:00
  • c9ff912b2f SEC-723: Change PreAuthenticatedAuthenticationProvider to reject authentication tokens with null credentials. Also introduced a property "throwExceptionWhenTokenIsRejected" which raises a BadCredentialsException when the toke is invalid. Luke Taylor 2008-03-18 18:29:48 +00:00
  • 163fb1052f SEC-721: Call Principal.getName() in AbstractAuthenticationToken.getName() if principal instaceof Principal Luke Taylor 2008-03-18 18:06:56 +00:00
  • 2df2eaa169 SEC-719: Introduced base class for J2eeBasedPreAuthenticatedWebAuthenticationDetailsSource to extract non-http specific functionality (for use in portlet version). Luke Taylor 2008-03-18 17:22:02 +00:00
  • 52b92b209c Removed out of date email address for Ben. Luke Taylor 2008-03-17 22:44:13 +00:00
  • cd61d76aaf SEC-719: Refactor portlet code to make more use of core classes http://jira.springframework.org/browse/SEC-719. Removed portlet-specific cache interface and implementations in favour of using (identical) ones from core. Luke Taylor 2008-03-17 14:45:44 +00:00
  • 8f7b216de3 Import cleaning, removal of unnecessary constructors etc based on eclipse warnings Luke Taylor 2008-03-17 14:10:22 +00:00
  • abd5e384fe removed unused eh-cache config file Luke Taylor 2008-03-17 14:07:19 +00:00
  • 114969f7f7 SEC-706: Removed LDAP dependencies from tutorial app, since we now have a separate sample Luke Taylor 2008-03-17 14:06:13 +00:00
  • 60de6314d4 Replaced casting to check validity of provider list with call to Assert.isInstanceof. Luke Taylor 2008-03-17 13:50:37 +00:00
  • d008ecde56 SEC-368: Wrong name in pom.xml Luke Taylor 2008-03-17 11:08:21 +00:00
  • bd5172ffbc SEC-368: Extra spelling corrections in captcha. Also general tidying up of comments and corrections of log messages Luke Taylor 2008-03-17 11:06:32 +00:00
  • 4586183f17 SEC-717: Resolve UserDetails.getAuthorities() sort logic issue. Ben Alex 2008-03-16 04:51:33 +00:00
  • 072b76e516 SEC-717: Resolve UserDetails.getAuthorities() sort logic issue. Ben Alex 2008-03-16 04:49:28 +00:00
  • 18aa13c7ec SEC-717: Resolve UserDetails.getAuthorities() sort logic issue. Ben Alex 2008-03-16 04:49:18 +00:00
  • 25d6792ca1 SEC-717: Resolve UserDetails.getAuthorities() sort logic issue. Ben Alex 2008-03-16 04:49:12 +00:00
  • 7d6c858b1d SEC-717: Resolve UserDetails.getAuthorities() sort logic issue. Ben Alex 2008-03-16 04:49:05 +00:00
  • c5f63d00cc SEC-717: Resolve UserDetails.getAuthorities() sort logic issue. Ben Alex 2008-03-16 04:17:56 +00:00
  • e4c6022b36 SEC-718: Support additional HTTP methods. Ben Alex 2008-03-16 04:14:21 +00:00
  • 6bc0585e4a SEC-717: Resolve UserDetails.getAuthorities() sort logic issue. Ben Alex 2008-03-16 04:02:55 +00:00
  • 820c529809 Information on paid support. Ben Alex 2008-03-16 04:02:14 +00:00
  • 1e28a67410 SEC-706: Added sample app with LDAP configuration Luke Taylor 2008-03-14 12:14:27 +00:00
  • 5743763599 SEC-625: Remove references to FilterToBeanProxy Luke Taylor 2008-03-13 18:52:31 +00:00
  • 1492918674 removed jalopy file Luke Taylor 2008-03-13 17:01:26 +00:00
  • 5d6ec8ed71 SEC-702: Updated use of UsernameNotFoundException to set extraInformation property Luke Taylor 2008-03-13 16:49:19 +00:00
  • 712f1770d9 SEC-714: Refactor PreAuthenticatedGrantedAuthoritiesSetter and PreAuthenticatedGrantedAuthoritiesRetriever http://jira.springframework.org/browse/SEC-714 Luke Taylor 2008-03-13 16:03:18 +00:00
  • 42a80931c1 SEC-671: Changed AuthenticationDetailsSource to take an object as argument instead of an HttpServletRequest and renamed AuthenticationDetailsSourceImpl to WebAuthenticationDetailsSource. Also removed some preauth dependencies on commons lang Luke Taylor 2008-03-13 14:42:38 +00:00
  • df0d52ada7 SEC-708: Improve generation of XSD file from Relax NG schema http://jira.springframework.org/browse/SEC-708. Committed XSL transformed XSD file and some minor changes to organisation of RNC file. Luke Taylor 2008-03-13 10:33:28 +00:00
  • 3a364a3343 SEC-713: Made MethodDefinitionAdvisor an infrastructure bean as required by Spring 2.0.7+ and upgraded to Spring 2.0.8 Luke Taylor 2008-03-11 17:53:04 +00:00