ca16a9608c
Corrected typo
Luke Taylor
2008-02-08 11:26:38 +00:00
549de2927e
SEC-641: Avoid direct use of external classes in namespace parsing.
Luke Taylor
2008-02-07 15:03:27 +00:00
6e93ec92eb
Added db creation message.
Luke Taylor
2008-02-07 13:35:27 +00:00
28153f2c7f
Added TestDataSource class to cut down verbosity of in-memory test databases and to implement DisposableBean, so the database is destroyed when the application context containing it is closed.
Luke Taylor
2008-02-07 13:33:15 +00:00
208d1ee8e2
SEC-456: Added test class for UserDetailsServiceLdapAuthoritiesPopulator
Luke Taylor
2008-02-07 13:31:25 +00:00
9292317e1c
Deleted unused context file.
Luke Taylor
2008-02-07 13:30:03 +00:00
b6d3ed135d
SEC-456: Added class Javadoc
Luke Taylor
2008-02-06 17:24:45 +00:00
b2cc817835
SEC-456: Basic LDAP authorities populator that delegates to a UserDetailsService.
Luke Taylor
2008-02-06 17:22:27 +00:00
99621a225d
SEC-481: Refactoring commence method of AuthenticationProcessingFilterEtryPoint to allow alternative redirect options. Extracted two methods, "buildRedirectUrlToLoginPage" and "buildHttpsRedirectUrlForRequest" and introduced a RedirectUrlBuilder class for assembling the URLs from schemes, ports etc.
Luke Taylor
2008-02-06 16:38:47 +00:00
adbf18a091
SEC-507: Updated JSR-250 impl to include better support for PermitAll and DenyAll as suggested by Ryan Heaton. Includes JSR-250 voter which is now used by AnnotationDriverbeanDefinitionParser.
Luke Taylor
2008-02-06 13:14:46 +00:00
c1895acb6b
Changed package doc which mentioned adding filter to web.xml rather than filter chain.
Luke Taylor
2008-02-06 10:36:25 +00:00
98ccaa61e7
SEC-532: test class for ObjectIdentityRetrievalStrategyImpl
Andrei Stefan
2008-02-06 09:26:39 +00:00
5d09f1264b
SEC-532: Added test method for different hashCode calculation when different Serializable classes are used (the method is commmented as, now, it doesn't pass the test)
Andrei Stefan
2008-02-06 09:26:05 +00:00
419a7a6426
SEC-532: added more test methods for JdbcAclService implementation
Andrei Stefan
2008-02-06 09:24:13 +00:00
2c0c731aaa
SEC-552: Removed accidentally commited incomplete caching-related classes.
Luke Taylor
2008-02-05 16:59:41 +00:00
b82fbb698d
SEC-641: Updated to set "source" values on BeanDefinitions where possible.
Luke Taylor
2008-02-05 14:48:39 +00:00
8859034d11
SEC-641: Reomove use of SecurityConfigException during parsing.
Luke Taylor
2008-02-05 11:46:27 +00:00
717ab0b3cc
SEC-641: Replaced use of Assert with more tooling friendly calls to parserContext.getReaderContext().error()
Luke Taylor
2008-02-05 11:29:52 +00:00
abb6402cec
Import cleaning.
Luke Taylor
2008-02-05 10:51:52 +00:00
adba67326f
Removed accidentally committed version of tutorial app context file.
Luke Taylor
2008-02-04 21:27:35 +00:00
84c7ac5e57
SEC-664: Removed validateUserDetails method from AbstractRememberMeServices, wrapped the UserDetailsService in a status-checking one and added a catch block for AccountStatusExceptions. Also some minor tidying up of other remember-me classes.
Luke Taylor
2008-02-04 21:26:07 +00:00
d3f26f09b6
Added support for locking user accounts in namespace <user-service> "user" elements (for use in testing).
Luke Taylor
2008-02-04 21:23:49 +00:00
2343577fec
Update new X509 namespace config to use status checking of user accounts by default.
Luke Taylor
2008-02-04 19:43:09 +00:00
600ab04cc7
SEC-663: Added null check for pre-authenticated principal value (and skip authentication attempt if null).
Luke Taylor
2008-02-04 19:36:44 +00:00
3f1ab233dc
SEC-662: Add check for a null authentication object returned by provider and skip passing it to session controller.
Luke Taylor
2008-02-04 19:27:12 +00:00
9be3f20faa
Andrei Stefan
2008-02-04 16:44:11 +00:00
26fa0c143b
Added myself to the users list because I can :P
Ray Krueger
2008-02-04 14:25:12 +00:00
1191701d8b
SEC-372: Added switchFailureUrl to SwitchUserProcessingFilter. Also did some refactoring to use the StatusCheckingUserDetailsService decorator, rather than checking status internally.
Luke Taylor
2008-02-04 14:02:30 +00:00
b93583164d
SEC-659: Change CAS sample to use authentication-manager element.
Luke Taylor
2008-02-04 00:12:56 +00:00
424ac4f117
Commented out tests which are breaking build.
Luke Taylor
2008-02-02 22:03:35 +00:00
ab5d416e00
SEC-516: Make default SavedRequest a "GET" in test to prevent NPE.
Luke Taylor
2008-02-02 21:41:41 +00:00
c0e2842f90
General cleanup and removal of unused stuff
Ray Krueger
2008-02-01 16:32:20 +00:00
e42fdf29ae
Don't add exception to session if allowSessionCreation is false.
Luke Taylor
2008-02-01 16:03:56 +00:00
3da2471b7f
Some tidying up of OpenID login form.
Luke Taylor
2008-02-01 16:01:34 +00:00
abe62f9146
Modified to store the login name in the session when login fails, so that it is available to the view (as in AuthenticationProcessingFilter).
Luke Taylor
2008-02-01 16:00:46 +00:00
842dec0180
Andrei Stefan
2008-02-01 15:35:20 +00:00
677012a5de
Added Robin as author.
Luke Taylor
2008-02-01 15:20:37 +00:00
bd9138d78a
Import cleaning.
Luke Taylor
2008-02-01 14:38:03 +00:00
287726335a
OpenID sample application.
Luke Taylor
2008-02-01 14:32:54 +00:00
df1def412e
Changed to using new alias for security filter chain in samples.
Luke Taylor
2008-02-01 14:28:04 +00:00
298546014a
SEC-659: Added authentication-manager element to allow users to define an alias for the internal authentication manager.
Luke Taylor
2008-02-01 14:25:07 +00:00
86f7b47fac
Updated jetty plugin to 6.1.7
Luke Taylor
2008-02-01 14:18:23 +00:00
2ad0c2cbd0
Corrected check on whether delegate implements Ordered interface.
Luke Taylor
2008-02-01 14:02:01 +00:00
0d9c1924fb
Added check for null consumer, removed unused "errorPage" property.
Luke Taylor
2008-02-01 14:00:28 +00:00
ca75905c3e
SEC-658: Add support for ldap-user-service to AuthenticationProviderBeanDefinitionParser.
Luke Taylor
2008-01-31 20:32:31 +00:00
2c6fb3d1c9
Added extra tests for jdbc-user-details service to make sure it works within an <authentication-provider> element.
Luke Taylor
2008-01-31 20:30:37 +00:00
e82dfd3f1a
Added some further tests for LDAP searching with a different user search base.
Luke Taylor
2008-01-31 17:44:52 +00:00
feb790ea83
SEC-486: Added determineExpiredUrl method to ConcurrentSessionFilter
Luke Taylor
2008-01-31 16:25:50 +00:00
feadb3582a
SEC-516: TargetUrlResolver path to avoid redirecting to POST requests.
Luke Taylor
2008-01-31 16:05:25 +00:00
9f45f95fab
SEC-491: Add alternative options for determining logout URL.
Luke Taylor
2008-01-31 15:48:04 +00:00
a305c9111f
SEC-576: Add check for null pre-auth principal and return null if found.
Luke Taylor
2008-01-31 14:50:12 +00:00
5394350cc8
SEC-576: Renamed PreAuthenticateduserDetailsService to AuthenticationUserdetailsService and changed signature accordingly.
Luke Taylor
2008-01-31 14:24:12 +00:00
311add2270
SEC-300: Applied Andreas Senft's patch for unwrapping exceptions in ExceptionTranslationFilter to obtain the cause.
Luke Taylor
2008-01-30 16:15:02 +00:00
3b6ce862f3
SEC-342: Change ObjectDefinitionSource to return a Collection instead of an Iterator.
Luke Taylor
2008-01-30 15:43:40 +00:00
d695f5002c
SEC-654: Made ConfigAttributeDefinition immutable, added several constructors to simplify its use. Removed MethodDefinitionMapping and FilterInvocationDefinitionMapping.
Luke Taylor
2008-01-30 15:17:30 +00:00
1dc80b5665
Removed openid from sandbox pom.xml as it's been moved to main project
Luke Taylor
2008-01-30 14:45:11 +00:00
c7754d7bee
SEC-473: Reduce the number of "cookie methods" in AbstractRememberMeServices.
Luke Taylor
2008-01-29 22:28:04 +00:00
00b5c0e61b
Andrei Stefan
2008-01-29 18:36:22 +00:00
f121b6ac90
Fixed tests which were making assumptions about ordering within sets.
Luke Taylor
2008-01-29 18:35:56 +00:00
aa0744a705
test class for EhCacheBasedAclCache
Andrei Stefan
2008-01-29 17:42:39 +00:00
944c7e9665
Andrei Stefan
2008-01-29 17:42:05 +00:00
e37d0b0bb1
SEC-543: sessionsUsedByPrincipal only needs to be added to "principals" map when it is first created.
Luke Taylor
2008-01-29 16:28:17 +00:00
379b7ab337
SEC-543: Moved logging out of synchronized block
Luke Taylor
2008-01-29 16:04:49 +00:00
9fe181046b
SEC-543: Added null guard clauses to reduce nesting and increase readability.
Luke Taylor
2008-01-29 15:55:29 +00:00
c9de2f6c9f
SEC-532: Remove FilterInvocationDefinitionSource-related classes which are no longer needed.
Luke Taylor
2008-01-29 15:09:20 +00:00
a0ee7fb6fd
SEC-532: Madded FilterinvocationDefinitionSourceMapping package scoped
Luke Taylor
2008-01-29 13:08:12 +00:00
8e5b608ee9
SEC-532: Removed FilterInvocationDecorator and tests.
Luke Taylor
2008-01-29 12:34:01 +00:00
059ac644bb
SEC-645: Deprecated old X.509 provider.
Luke Taylor
2008-01-29 11:50:33 +00:00
95c6ecdb1e
SEC-468: Added Mike Wiesner's patch for AspectJ annotation support.
Luke Taylor
2008-01-29 11:33:38 +00:00
ef428d2c22
Moved test class to correct source tree
Luke Taylor
2008-01-29 10:57:44 +00:00
e63fa0f610
SEC-418: Changed interface SwitchAuthorityChanger to return List rather than expecting modification of passed in List of authorities.
Luke Taylor
2008-01-28 19:26:30 +00:00
b253510127
SEC-418: Applied patch from issue.
Luke Taylor
2008-01-28 19:24:45 +00:00
0be34cdcc1
SEC-536: Added messages for generic UserDetails status checks.
Luke Taylor
2008-01-28 18:19:23 +00:00
c9dee10704
SEC-536: Added UserDetailsService decorator class which will throw an appropriate exception if the returned UserDetails object has a status of locked, disabled etc.
Luke Taylor
2008-01-28 18:10:43 +00:00
f0c15f5b1a
SEC-25: Rolled back addition of EJB integration docbook to ref manual.
Luke Taylor
2008-01-28 17:33:08 +00:00
934e59a562
SEC-652: Fixed CasAuthenticationProvider to be compatible with Ray's recent AuthoritiesPopulator refactoring.
Luke Taylor
2008-01-28 16:05:39 +00:00
26ea65ddb1
SEC-652: Add a trustPassword to AbstractTicketValidator for use with password protected keystores (as in the sample application).
Luke Taylor
2008-01-28 16:04:38 +00:00
46a69b6d93
SEC-652: CAS sample application and server using maven jetty plugin.
Luke Taylor
2008-01-28 16:03:28 +00:00
511ebb5af4
Reformat pom.xml.
Luke Taylor
2008-01-28 14:30:15 +00:00
eb620f09eb
Switched preauth default namespace to "beans" for readability.
Luke Taylor
2008-01-28 13:22:50 +00:00
5738a51040
SEC-651: Support for ldap-user-service bean.
Luke Taylor
2008-01-28 00:47:34 +00:00
544df3ea09
Updated SpringSecurityLdapTemplate to include base LDAP context in returned DirContextAdapter entry to make sure the result gives a correct value for getNameInNamespace(). This is necessary when a search is used to obtain entries to pass to DefaultLdapAuthoritiesPopulator, for example.
Luke Taylor
2008-01-28 00:39:42 +00:00
80b6111641
SEC-650: Change default scope to sub-tree.
Luke Taylor
2008-01-28 00:24:54 +00:00
e6d6e88117
Corrections to calculated order values from "before" and "after" attributes.
Luke Taylor
2008-01-27 22:46:24 +00:00
acf5601714
SEC-645: Reimplementation of X509 provider and namespace implementation.
Luke Taylor
2008-01-27 22:45:44 +00:00
9af7ab68bf
Removed duplicate setting of bean property in BasicAuthenticationBeanDefinitionParser.
Luke Taylor
2008-01-27 20:48:37 +00:00
d8d657da7f
Removed classname from log message (normally output by log4j anyway)
Luke Taylor
2008-01-27 20:44:58 +00:00
aeba732ba5
SEC-647: Created separate "certificates" directory so SSL certificates and keys can be shared between different sample applications. Added key for user "scott" and separate certificate authority pem file (can be installed in a browser).
Luke Taylor
2008-01-27 20:42:10 +00:00
82940db6c8
SEC-648: Added custom-authentication-provider support.
Luke Taylor
2008-01-27 13:31:34 +00:00
dbc901fba9
Deleted
Luke Taylor
2008-01-27 13:30:11 +00:00
384af268ab
Import cleaning.
Luke Taylor
2008-01-27 13:28:58 +00:00
c7792458b4
SEC-645: Reimplementation of X509 authentication.
Luke Taylor
2008-01-27 11:12:50 +00:00
718eddadd7
Promoting OpenID out of the Sandbox
Ray Krueger
2008-01-27 02:57:57 +00:00
ae71e9a5bd
SEC-632: Changed user-filter to custom-filter to avoid confusion with system "users".
Luke Taylor
2008-01-27 00:48:53 +00:00
cd16dac290
SEC-648: Added custom-authentication-provider element.
Luke Taylor
2008-01-27 00:42:35 +00:00
e852cf53a8
SEC-644: Fix broken NtlmProcessingFilter and add AuthenticationDetailsSource to it.
Luke Taylor
2008-01-27 00:31:55 +00:00
619c7b0dbf
SEC-632: Explicit filter chain ordering is now achieved using "after" or "before". Setting the order value directly in the context is fragile due to potential future changes in the order values of standard filters.
Luke Taylor
2008-01-26 23:56:04 +00:00
e44e641106
SEC-647: Updated server keystore (new certificate using our own Test CA) and added client certificates for users rod and dianne.
Luke Taylor
2008-01-26 17:21:23 +00:00
0005da3b63
Corrected spelling of class name.
Luke Taylor
2008-01-26 11:36:24 +00:00
83ecb3e9e0
test classes
Andrei Stefan
2008-01-26 11:35:49 +00:00