Commit Graph

  • ca16a9608c Corrected typo Luke Taylor 2008-02-08 11:26:38 +00:00
  • 549de2927e SEC-641: Avoid direct use of external classes in namespace parsing. Luke Taylor 2008-02-07 15:03:27 +00:00
  • 6e93ec92eb Added db creation message. Luke Taylor 2008-02-07 13:35:27 +00:00
  • 28153f2c7f Added TestDataSource class to cut down verbosity of in-memory test databases and to implement DisposableBean, so the database is destroyed when the application context containing it is closed. Luke Taylor 2008-02-07 13:33:15 +00:00
  • 208d1ee8e2 SEC-456: Added test class for UserDetailsServiceLdapAuthoritiesPopulator Luke Taylor 2008-02-07 13:31:25 +00:00
  • 9292317e1c Deleted unused context file. Luke Taylor 2008-02-07 13:30:03 +00:00
  • b6d3ed135d SEC-456: Added class Javadoc Luke Taylor 2008-02-06 17:24:45 +00:00
  • b2cc817835 SEC-456: Basic LDAP authorities populator that delegates to a UserDetailsService. Luke Taylor 2008-02-06 17:22:27 +00:00
  • 99621a225d SEC-481: Refactoring commence method of AuthenticationProcessingFilterEtryPoint to allow alternative redirect options. Extracted two methods, "buildRedirectUrlToLoginPage" and "buildHttpsRedirectUrlForRequest" and introduced a RedirectUrlBuilder class for assembling the URLs from schemes, ports etc. Luke Taylor 2008-02-06 16:38:47 +00:00
  • adbf18a091 SEC-507: Updated JSR-250 impl to include better support for PermitAll and DenyAll as suggested by Ryan Heaton. Includes JSR-250 voter which is now used by AnnotationDriverbeanDefinitionParser. Luke Taylor 2008-02-06 13:14:46 +00:00
  • c1895acb6b Changed package doc which mentioned adding filter to web.xml rather than filter chain. Luke Taylor 2008-02-06 10:36:25 +00:00
  • 98ccaa61e7 SEC-532: test class for ObjectIdentityRetrievalStrategyImpl Andrei Stefan 2008-02-06 09:26:39 +00:00
  • 5d09f1264b SEC-532: Added test method for different hashCode calculation when different Serializable classes are used (the method is commmented as, now, it doesn't pass the test) Andrei Stefan 2008-02-06 09:26:05 +00:00
  • 419a7a6426 SEC-532: added more test methods for JdbcAclService implementation Andrei Stefan 2008-02-06 09:24:13 +00:00
  • 2c0c731aaa SEC-552: Removed accidentally commited incomplete caching-related classes. Luke Taylor 2008-02-05 16:59:41 +00:00
  • b82fbb698d SEC-641: Updated to set "source" values on BeanDefinitions where possible. Luke Taylor 2008-02-05 14:48:39 +00:00
  • 8859034d11 SEC-641: Reomove use of SecurityConfigException during parsing. Luke Taylor 2008-02-05 11:46:27 +00:00
  • 717ab0b3cc SEC-641: Replaced use of Assert with more tooling friendly calls to parserContext.getReaderContext().error() Luke Taylor 2008-02-05 11:29:52 +00:00
  • abb6402cec Import cleaning. Luke Taylor 2008-02-05 10:51:52 +00:00
  • adba67326f Removed accidentally committed version of tutorial app context file. Luke Taylor 2008-02-04 21:27:35 +00:00
  • 84c7ac5e57 SEC-664: Removed validateUserDetails method from AbstractRememberMeServices, wrapped the UserDetailsService in a status-checking one and added a catch block for AccountStatusExceptions. Also some minor tidying up of other remember-me classes. Luke Taylor 2008-02-04 21:26:07 +00:00
  • d3f26f09b6 Added support for locking user accounts in namespace <user-service> "user" elements (for use in testing). Luke Taylor 2008-02-04 21:23:49 +00:00
  • 2343577fec Update new X509 namespace config to use status checking of user accounts by default. Luke Taylor 2008-02-04 19:43:09 +00:00
  • 600ab04cc7 SEC-663: Added null check for pre-authenticated principal value (and skip authentication attempt if null). Luke Taylor 2008-02-04 19:36:44 +00:00
  • 3f1ab233dc SEC-662: Add check for a null authentication object returned by provider and skip passing it to session controller. Luke Taylor 2008-02-04 19:27:12 +00:00
  • 9be3f20faa Andrei Stefan 2008-02-04 16:44:11 +00:00
  • 26fa0c143b Added myself to the users list because I can :P Ray Krueger 2008-02-04 14:25:12 +00:00
  • 1191701d8b SEC-372: Added switchFailureUrl to SwitchUserProcessingFilter. Also did some refactoring to use the StatusCheckingUserDetailsService decorator, rather than checking status internally. Luke Taylor 2008-02-04 14:02:30 +00:00
  • b93583164d SEC-659: Change CAS sample to use authentication-manager element. Luke Taylor 2008-02-04 00:12:56 +00:00
  • 424ac4f117 Commented out tests which are breaking build. Luke Taylor 2008-02-02 22:03:35 +00:00
  • ab5d416e00 SEC-516: Make default SavedRequest a "GET" in test to prevent NPE. Luke Taylor 2008-02-02 21:41:41 +00:00
  • c0e2842f90 General cleanup and removal of unused stuff Ray Krueger 2008-02-01 16:32:20 +00:00
  • e42fdf29ae Don't add exception to session if allowSessionCreation is false. Luke Taylor 2008-02-01 16:03:56 +00:00
  • 3da2471b7f Some tidying up of OpenID login form. Luke Taylor 2008-02-01 16:01:34 +00:00
  • abe62f9146 Modified to store the login name in the session when login fails, so that it is available to the view (as in AuthenticationProcessingFilter). Luke Taylor 2008-02-01 16:00:46 +00:00
  • 842dec0180 Andrei Stefan 2008-02-01 15:35:20 +00:00
  • 677012a5de Added Robin as author. Luke Taylor 2008-02-01 15:20:37 +00:00
  • bd9138d78a Import cleaning. Luke Taylor 2008-02-01 14:38:03 +00:00
  • 287726335a OpenID sample application. Luke Taylor 2008-02-01 14:32:54 +00:00
  • df1def412e Changed to using new alias for security filter chain in samples. Luke Taylor 2008-02-01 14:28:04 +00:00
  • 298546014a SEC-659: Added authentication-manager element to allow users to define an alias for the internal authentication manager. Luke Taylor 2008-02-01 14:25:07 +00:00
  • 86f7b47fac Updated jetty plugin to 6.1.7 Luke Taylor 2008-02-01 14:18:23 +00:00
  • 2ad0c2cbd0 Corrected check on whether delegate implements Ordered interface. Luke Taylor 2008-02-01 14:02:01 +00:00
  • 0d9c1924fb Added check for null consumer, removed unused "errorPage" property. Luke Taylor 2008-02-01 14:00:28 +00:00
  • ca75905c3e SEC-658: Add support for ldap-user-service to AuthenticationProviderBeanDefinitionParser. Luke Taylor 2008-01-31 20:32:31 +00:00
  • 2c6fb3d1c9 Added extra tests for jdbc-user-details service to make sure it works within an <authentication-provider> element. Luke Taylor 2008-01-31 20:30:37 +00:00
  • e82dfd3f1a Added some further tests for LDAP searching with a different user search base. Luke Taylor 2008-01-31 17:44:52 +00:00
  • feb790ea83 SEC-486: Added determineExpiredUrl method to ConcurrentSessionFilter Luke Taylor 2008-01-31 16:25:50 +00:00
  • feadb3582a SEC-516: TargetUrlResolver path to avoid redirecting to POST requests. Luke Taylor 2008-01-31 16:05:25 +00:00
  • 9f45f95fab SEC-491: Add alternative options for determining logout URL. Luke Taylor 2008-01-31 15:48:04 +00:00
  • a305c9111f SEC-576: Add check for null pre-auth principal and return null if found. Luke Taylor 2008-01-31 14:50:12 +00:00
  • 5394350cc8 SEC-576: Renamed PreAuthenticateduserDetailsService to AuthenticationUserdetailsService and changed signature accordingly. Luke Taylor 2008-01-31 14:24:12 +00:00
  • 311add2270 SEC-300: Applied Andreas Senft's patch for unwrapping exceptions in ExceptionTranslationFilter to obtain the cause. Luke Taylor 2008-01-30 16:15:02 +00:00
  • 3b6ce862f3 SEC-342: Change ObjectDefinitionSource to return a Collection instead of an Iterator. Luke Taylor 2008-01-30 15:43:40 +00:00
  • d695f5002c SEC-654: Made ConfigAttributeDefinition immutable, added several constructors to simplify its use. Removed MethodDefinitionMapping and FilterInvocationDefinitionMapping. Luke Taylor 2008-01-30 15:17:30 +00:00
  • 1dc80b5665 Removed openid from sandbox pom.xml as it's been moved to main project Luke Taylor 2008-01-30 14:45:11 +00:00
  • c7754d7bee SEC-473: Reduce the number of "cookie methods" in AbstractRememberMeServices. Luke Taylor 2008-01-29 22:28:04 +00:00
  • 00b5c0e61b Andrei Stefan 2008-01-29 18:36:22 +00:00
  • f121b6ac90 Fixed tests which were making assumptions about ordering within sets. Luke Taylor 2008-01-29 18:35:56 +00:00
  • aa0744a705 test class for EhCacheBasedAclCache Andrei Stefan 2008-01-29 17:42:39 +00:00
  • 944c7e9665 Andrei Stefan 2008-01-29 17:42:05 +00:00
  • e37d0b0bb1 SEC-543: sessionsUsedByPrincipal only needs to be added to "principals" map when it is first created. Luke Taylor 2008-01-29 16:28:17 +00:00
  • 379b7ab337 SEC-543: Moved logging out of synchronized block Luke Taylor 2008-01-29 16:04:49 +00:00
  • 9fe181046b SEC-543: Added null guard clauses to reduce nesting and increase readability. Luke Taylor 2008-01-29 15:55:29 +00:00
  • c9de2f6c9f SEC-532: Remove FilterInvocationDefinitionSource-related classes which are no longer needed. Luke Taylor 2008-01-29 15:09:20 +00:00
  • a0ee7fb6fd SEC-532: Madded FilterinvocationDefinitionSourceMapping package scoped Luke Taylor 2008-01-29 13:08:12 +00:00
  • 8e5b608ee9 SEC-532: Removed FilterInvocationDecorator and tests. Luke Taylor 2008-01-29 12:34:01 +00:00
  • 059ac644bb SEC-645: Deprecated old X.509 provider. Luke Taylor 2008-01-29 11:50:33 +00:00
  • 95c6ecdb1e SEC-468: Added Mike Wiesner's patch for AspectJ annotation support. Luke Taylor 2008-01-29 11:33:38 +00:00
  • ef428d2c22 Moved test class to correct source tree Luke Taylor 2008-01-29 10:57:44 +00:00
  • e63fa0f610 SEC-418: Changed interface SwitchAuthorityChanger to return List rather than expecting modification of passed in List of authorities. Luke Taylor 2008-01-28 19:26:30 +00:00
  • b253510127 SEC-418: Applied patch from issue. Luke Taylor 2008-01-28 19:24:45 +00:00
  • 0be34cdcc1 SEC-536: Added messages for generic UserDetails status checks. Luke Taylor 2008-01-28 18:19:23 +00:00
  • c9dee10704 SEC-536: Added UserDetailsService decorator class which will throw an appropriate exception if the returned UserDetails object has a status of locked, disabled etc. Luke Taylor 2008-01-28 18:10:43 +00:00
  • f0c15f5b1a SEC-25: Rolled back addition of EJB integration docbook to ref manual. Luke Taylor 2008-01-28 17:33:08 +00:00
  • 934e59a562 SEC-652: Fixed CasAuthenticationProvider to be compatible with Ray's recent AuthoritiesPopulator refactoring. Luke Taylor 2008-01-28 16:05:39 +00:00
  • 26ea65ddb1 SEC-652: Add a trustPassword to AbstractTicketValidator for use with password protected keystores (as in the sample application). Luke Taylor 2008-01-28 16:04:38 +00:00
  • 46a69b6d93 SEC-652: CAS sample application and server using maven jetty plugin. Luke Taylor 2008-01-28 16:03:28 +00:00
  • 511ebb5af4 Reformat pom.xml. Luke Taylor 2008-01-28 14:30:15 +00:00
  • eb620f09eb Switched preauth default namespace to "beans" for readability. Luke Taylor 2008-01-28 13:22:50 +00:00
  • 5738a51040 SEC-651: Support for ldap-user-service bean. Luke Taylor 2008-01-28 00:47:34 +00:00
  • 544df3ea09 Updated SpringSecurityLdapTemplate to include base LDAP context in returned DirContextAdapter entry to make sure the result gives a correct value for getNameInNamespace(). This is necessary when a search is used to obtain entries to pass to DefaultLdapAuthoritiesPopulator, for example. Luke Taylor 2008-01-28 00:39:42 +00:00
  • 80b6111641 SEC-650: Change default scope to sub-tree. Luke Taylor 2008-01-28 00:24:54 +00:00
  • e6d6e88117 Corrections to calculated order values from "before" and "after" attributes. Luke Taylor 2008-01-27 22:46:24 +00:00
  • acf5601714 SEC-645: Reimplementation of X509 provider and namespace implementation. Luke Taylor 2008-01-27 22:45:44 +00:00
  • 9af7ab68bf Removed duplicate setting of bean property in BasicAuthenticationBeanDefinitionParser. Luke Taylor 2008-01-27 20:48:37 +00:00
  • d8d657da7f Removed classname from log message (normally output by log4j anyway) Luke Taylor 2008-01-27 20:44:58 +00:00
  • aeba732ba5 SEC-647: Created separate "certificates" directory so SSL certificates and keys can be shared between different sample applications. Added key for user "scott" and separate certificate authority pem file (can be installed in a browser). Luke Taylor 2008-01-27 20:42:10 +00:00
  • 82940db6c8 SEC-648: Added custom-authentication-provider support. Luke Taylor 2008-01-27 13:31:34 +00:00
  • dbc901fba9 Deleted Luke Taylor 2008-01-27 13:30:11 +00:00
  • 384af268ab Import cleaning. Luke Taylor 2008-01-27 13:28:58 +00:00
  • c7792458b4 SEC-645: Reimplementation of X509 authentication. Luke Taylor 2008-01-27 11:12:50 +00:00
  • 718eddadd7 Promoting OpenID out of the Sandbox Ray Krueger 2008-01-27 02:57:57 +00:00
  • ae71e9a5bd SEC-632: Changed user-filter to custom-filter to avoid confusion with system "users". Luke Taylor 2008-01-27 00:48:53 +00:00
  • cd16dac290 SEC-648: Added custom-authentication-provider element. Luke Taylor 2008-01-27 00:42:35 +00:00
  • e852cf53a8 SEC-644: Fix broken NtlmProcessingFilter and add AuthenticationDetailsSource to it. Luke Taylor 2008-01-27 00:31:55 +00:00
  • 619c7b0dbf SEC-632: Explicit filter chain ordering is now achieved using "after" or "before". Setting the order value directly in the context is fragile due to potential future changes in the order values of standard filters. Luke Taylor 2008-01-26 23:56:04 +00:00
  • e44e641106 SEC-647: Updated server keystore (new certificate using our own Test CA) and added client certificates for users rod and dianne. Luke Taylor 2008-01-26 17:21:23 +00:00
  • 0005da3b63 Corrected spelling of class name. Luke Taylor 2008-01-26 11:36:24 +00:00
  • 83ecb3e9e0 test classes Andrei Stefan 2008-01-26 11:35:49 +00:00