Commit Graph

  • c2a13b0aa8 [maven-release-plugin] rollback the release of release_1_0_6 Luke Taylor 2007-12-24 16:32:46 +00:00
  • ad45967cef [maven-release-plugin] prepare release release_1_0_6 Luke Taylor 2007-12-24 16:26:44 +00:00
  • bdd78ced7f Corrected scm element Luke Taylor 2007-12-24 16:15:11 +00:00
  • 9174fb7746 Removed scm element from core and core-tiger Luke Taylor 2007-12-24 16:10:34 +00:00
  • b5ac6e42e3 Reinstated version as 1.0.6-SNAPSHOT after mvn release plugin failure Luke Taylor 2007-12-24 16:07:24 +00:00
  • e3247231d7 [maven-release-plugin] prepare release release_1_0_6 Luke Taylor 2007-12-24 16:00:00 +00:00
  • ab022a5ed3 testing svn commit Luke Taylor 2007-12-24 15:56:53 +00:00
  • 18d8084744 Fix jetty plugin version at 6.1.6. Luke Taylor 2007-12-24 14:51:50 +00:00
  • 1216673deb Fix jetty plugin version at 6.1.6. Luke Taylor 2007-12-24 14:48:45 +00:00
  • 7ee049c824 Refactored SwitchUserProcessingFilter to extend SpringSecurityFilter. Luke Taylor 2007-12-23 16:41:30 +00:00
  • 5f1eea42fc Moved configuration of security interceptors with access and authentication manangers from post processing stage to bean creation stage. Luke Taylor 2007-12-23 16:40:29 +00:00
  • 46c99d1991 Converted tutorial context file to match namespace changes. Luke Taylor 2007-12-23 16:36:44 +00:00
  • 5da5bfb7bb Added "mvn compile" with JDK 1.4 as extra check in build process. Luke Taylor 2007-12-23 15:07:13 +00:00
  • 27de29f469 Corrected cut and paste error when parsing jdbc-user-service within AuthenticationProvider BDP. Luke Taylor 2007-12-23 01:26:46 +00:00
  • ea8914f9ba Moved Http post processor bean name to BeanIds class. Luke Taylor 2007-12-23 01:06:22 +00:00
  • 9d671fbdbf Deleted original Ldap BD parser. Luke Taylor 2007-12-23 01:05:35 +00:00
  • 14e68618a5 Make constants class abstract. Luke Taylor 2007-12-23 01:02:48 +00:00
  • 46285a0ec0 SwitchUserProcessingFilter should come after FilterSecurityInterceptor (See SEC-376). Luke Taylor 2007-12-23 01:02:12 +00:00
  • a38ed3cfde Added check for multiple RememberMeServices beans. Luke Taylor 2007-12-23 00:18:14 +00:00
  • debfbe47cf Improvements to LDAP namespace configuration - splitting "ldap" element into ldap-server and ldap-authentication-provider. Also some minor changes to authentication-provider. Luke Taylor 2007-12-23 00:17:37 +00:00
  • d0490e6322 Upgraded maven surefire and cobertura plugins. Luke Taylor 2007-12-21 15:54:38 +00:00
  • cf80292de3 Changes to namespace reinstating authentication-provider element in preference to "repository" to wrap convey that a user-service will be used as to authenticate against. Also introduced separate password-encoder element for use within authentication-provider. Luke Taylor 2007-12-21 15:50:56 +00:00
  • 70286f1197 Fixed problem caused by maven-2.0.8 change in test classpath. ldif file wasn't being loaded for tests. Default path should be "classpath*:" not "classpath:". (See discussing in Spring's PathMatchingResourcePatternResolver). Luke Taylor 2007-12-20 20:53:26 +00:00
  • 6e74d925fb Boosted logging to try to resolve issues on bamboo server. Luke Taylor 2007-12-20 19:45:43 +00:00
  • 78e376312a Added logging of working directory location. Luke Taylor 2007-12-20 18:29:05 +00:00
  • 85b10f79c2 Made servlet-api integration into an attribute of http, rather than a child element since it has no configuration. Luke Taylor 2007-12-20 17:51:27 +00:00
  • 1c9bd8bf5f Updates to release description. Luke Taylor 2007-12-20 17:47:05 +00:00
  • e65cb9b472 Made group names singular and added "teller" role. Luke Taylor 2007-12-14 20:41:33 +00:00
  • 31c09896ea Fixed problem with relative name being used in (member={0}) search in DefaultAuthoritiesPopulator. Luke Taylor 2007-12-14 20:41:00 +00:00
  • 09f68400ec Add <intercept-methods> to example, but it is disabled in favour of @Secured annotation. Still, we include it so people can have a play around and switch between the two syntaxes easily in demos etc. Ben Alex 2007-12-14 19:56:31 +00:00
  • 55e4568003 Throw an exception instead of sending back a HTTP error code. This is necessary so any demonstration of upgrading from Servlet Spec authorization to Spring Security authorization, as the latter's ExceptionTranslationFilter expects specific exceptions to be thrown if you wish to commence the authentication process. Ben Alex 2007-12-14 19:44:50 +00:00
  • 2e4773525b Updated tutorial to allow authentication against ldap provider using <ldap /> namespace element. Luke Taylor 2007-12-14 19:18:18 +00:00
  • d90ff50686 Use Java 5 to illustrate annotation support. Ben Alex 2007-12-14 16:54:10 +00:00
  • 1a171ea316 SEC-595: Introduced loadUserAuthorities method. This can be overridden to allow loading of authorities with the authenticated user's credentials (by setting the security context). The Ldap ContextSource used in the authorities populator would also be configured with a SpringSecurityAuthentcationSource, to make use of the information in the security context. Luke Taylor 2007-12-14 14:13:39 +00:00
  • b1bc39a0df Provide some shell scripts that help with demos. These assume the application is deployed to http://localhost:8080/spring-security-samples-tutorial. Ben Alex 2007-12-14 02:45:01 +00:00
  • f4c3e701d5 Enhance sample to show method authorization. Ben Alex 2007-12-14 02:27:48 +00:00
  • 77d286c36f Enhance tutorial to also demonstrate Spring Security method authorization, and add a services layer accordingly. Ben Alex 2007-12-14 02:26:27 +00:00
  • fa510b3187 Modify attribute names to use "ref" instead of "id", plus use a hyphen as an attribute value separator rather than a colon. This was changed for compatibility with other components in the Spring Portfolio. tests pass. Ben Alex 2007-12-13 20:19:56 +00:00
  • 0f12d31d90 Corrected code for choosing entry point in namespace configuration. Luke Taylor 2007-12-12 19:44:54 +00:00
  • 7ff533735f Changes (made by Ben Hale) to support publishing of snapshots and releases to Spring S3 repository. Ben Alex 2007-12-12 19:06:12 +00:00
  • 6f7590eb05 Updates to sandbox to allow it to compile against latest core changes. Luke Taylor 2007-12-12 16:15:04 +00:00
  • 1cae1719bc Fix bean referencing error. Ben Alex 2007-12-11 19:18:44 +00:00
  • 2655955a40 Add MethodSecurityInterceptor, to more accurately reflect the capabilities offered by auto-config="true". Ben Alex 2007-12-11 19:14:34 +00:00
  • 9728f48adf Convert to using AopNamespaceUtils, to avoid potentially creating duplicate DefaultAdvisorAutoProxyCreator bean instances. Ben Alex 2007-12-11 18:46:20 +00:00
  • 82cfa722be Upgrade Spring-LDAP to 1.2.1 version. Luke Taylor 2007-12-11 18:08:44 +00:00
  • 1bbe6ca456 Proper comparison with auto-configure="true". Ben Alex 2007-12-11 16:44:24 +00:00
  • ca996de2dc Added tests for SpringSecurityAuthenticationSource. Luke Taylor 2007-12-10 23:37:08 +00:00
  • 894c90dadd Moved AbstractAuthenticationManagerTests into ProviderManager as tested methods have already been moved there (maven wasn't running Abstract* tests but they were actually failing). Luke Taylor 2007-12-10 23:36:27 +00:00
  • 32038d8b92 Tidying. Luke Taylor 2007-12-10 19:14:17 +00:00
  • 47dec4e597 Make getters in AbstractRememberMeServices protected rather than public Luke Taylor 2007-12-10 16:00:49 +00:00
  • ee31305fd5 Deprecated InitialDirContextFactory Luke Taylor 2007-12-10 15:29:26 +00:00
  • 5382627d4a Added property to LdapAuthenticationProvider to allow the credentials to be set either using the submitted password (the default) or the credentials from the loaded UserDetails object (which may be null if the attribute isn't readable). Luke Taylor 2007-12-09 23:46:28 +00:00
  • 78529f6d28 SEC-620: AuthenticationSource implementation. Luke Taylor 2007-12-09 23:44:15 +00:00
  • 5e0cb21c8d SEC-619: Added test class for LdapUserDetailsService. The LdapAuthoritiesPopulator interface and also implementations have been moved to the org.springframework.security.ldap package since they are now used by both the ldap provider and the user service. Luke Taylor 2007-12-09 18:40:28 +00:00
  • 4770c29094 Use hyphens in attribute names, and not Camel Case. This is to maintain consistency with the rest of Spring Portfolio. Camel Case was preserved for attribute values, consistent with Spring Portfolio usage such as autowiring modes (byName, byType etc). Ben Alex 2007-12-09 03:42:20 +00:00
  • 6ad176ce1a Tidying. Luke Taylor 2007-12-07 17:00:40 +00:00
  • 4984024314 SEC-618: Moved copyDetails method down to ProviderManager so that it can be called prior to checking if authentication is allowed by ConcurrentSessionController. Luke Taylor 2007-12-07 16:26:50 +00:00
  • 8e6e373a3b Removed unused import. Luke Taylor 2007-12-07 16:20:31 +00:00
  • 2b0ee23396 SEC-618: Move copyDetails method into ProviderManager and call it before checking with ConcurrentSessionController. Luke Taylor 2007-12-07 16:17:59 +00:00
  • 89cde2507d SEC-594: Set password on UserDetails object returned by BindAuthenticator. Luke Taylor 2007-12-07 16:04:43 +00:00
  • b12a4939df SEC-619: LdapUserDetailsService implementation. Luke Taylor 2007-12-07 13:16:44 +00:00
  • a569ff01e2 Tidying. Luke Taylor 2007-12-07 12:32:54 +00:00
  • 382dc50f3c SEC-299: Change ConcurrentSessionFilter to delegate to an array of LogoutHandlers rather than invalidating an expired session directly. Luke Taylor 2007-12-06 17:39:04 +00:00
  • cb980f12d5 Tidying. Luke Taylor 2007-12-06 17:26:04 +00:00
  • 628227f5e7 Corrected out of date comment (constructor doesn't create a session). Removed unnecessary default constructor. Luke Taylor 2007-12-06 16:53:35 +00:00
  • 4b8455c831 Tidying comments. Luke Taylor 2007-12-06 16:40:16 +00:00
  • 4c6e41af7d Tidying comments. Luke Taylor 2007-12-06 16:33:59 +00:00
  • c66a3ba323 @deprecate FilterToBeanProxy in favour of the simpler and Spring Core provided DelegatingFilterProxy. Ben Alex 2007-12-06 09:43:43 +00:00
  • ab23fe56ad Added log msg for loading of ldif files. Luke Taylor 2007-12-06 00:14:25 +00:00
  • a1abcc39d2 SEC-513: Minor work on LDAP UserDetailsManager implementation. Luke Taylor 2007-12-06 00:13:42 +00:00
  • e3432c2407 Some changes suggested by Spring LDAP guys to improve template usage. Luke Taylor 2007-12-06 00:13:00 +00:00
  • 4d133be0d0 Tidying. Luke Taylor 2007-12-06 00:12:24 +00:00
  • 3ddcc203bf LdapUserDetailsMapper now throws UnsupportedOperationException for mapUserToContext method as only subclasses of this which implement actual LDAP object classes should be used for writing to a directory. Luke Taylor 2007-12-06 00:12:06 +00:00
  • 22052115b6 SEC-617: Make LDAPAuthenticationProvider a standalone class. Luke Taylor 2007-12-05 14:39:46 +00:00
  • 88ab9671c6 Correct attribute name. Ben Alex 2007-12-04 14:24:53 +00:00
  • 9b6c798a52 SEC-496: <annotation-driven> element. Ben Alex 2007-12-04 14:14:17 +00:00
  • 949205b369 Correction of equals(Object) and hashCode() methods. Ben Alex 2007-12-04 12:44:40 +00:00
  • 85085abf9e Add namespace support for Servlet API integration. Ben Alex 2007-12-04 12:23:41 +00:00
  • a205f95c19 No need for an access denied page. Ben Alex 2007-12-04 11:24:54 +00:00
  • 8c3cc5c67b Add hash code support. Ben Alex 2007-12-04 11:21:39 +00:00
  • 8e7c540b16 General refactorings and improvements to namespace support, including autoDetect="true" attribute for <http> element. Ben Alex 2007-12-04 10:35:08 +00:00
  • 2441ab6d9a Move "realm" attribute to be on <http> element rather than <http-basic>. This faciltiates reuse with other mechanisms (like Digest) whilst also moving towards the <http-auto-configure> element (which benefits from having shared configuration in <http> as opposed to mechanism-specific elements). Ben Alex 2007-12-04 08:02:40 +00:00
  • d9ec944579 Refactor strings to static fields. To facilitate unit testing, package protected visibility was adopted for all element names, attribute names, and attribute default values. A public access modifier was used for all bean IDs assigned to bean definitions created by the BeanDefinitionParsers. Ben Alex 2007-12-04 07:12:08 +00:00
  • 4e55bd0117 Make extend Spring Security's exception, for consistency with all other Spring Security exceptions. Ben Alex 2007-12-04 06:58:43 +00:00
  • 9b4bb0ffd8 <repository> element and JdbcUserDetailsManager support. Ben Alex 2007-12-04 05:58:54 +00:00
  • 5f98ee6817 <repository> element and JdbcUserDetailsManager support. Ben Alex 2007-12-04 05:54:58 +00:00
  • 0b0b174eda Support <repository> and JbcUserDetailsManager. Ben Alex 2007-12-04 05:27:17 +00:00
  • 8cf46ad0f8 Remove, as not used. Ben Alex 2007-12-04 05:12:39 +00:00
  • 8c9138b443 Typos. Ben Alex 2007-12-04 02:11:16 +00:00
  • 021f03487e Enhancements to correctly handle authentication failures. Ben Alex 2007-12-04 01:50:45 +00:00
  • 2a83843e7d Correct username key. Ben Alex 2007-12-04 01:46:26 +00:00
  • 75391e89de Tidied up Id tag. Luke Taylor 2007-12-04 00:01:09 +00:00
  • 794795712d Parameter renamed. Luke Taylor 2007-12-04 00:00:50 +00:00
  • 97030e8942 Changed LDAP namespace parsing to make sure LDAP provider is registered with ProviderManager. Luke Taylor 2007-12-03 23:58:38 +00:00
  • ac0e308354 Updated spring and acegi version numbers in petclinic tutorial file. Luke Taylor 2007-12-03 23:15:29 +00:00
  • 89d04b54bd Updated version numbers in petclinic tutorial file. Luke Taylor 2007-12-03 23:14:10 +00:00
  • 248d97c9d6 SEC-513: Added support for cache flushing after updating or deleting data in JdbcUserDetailsManager. Luke Taylor 2007-12-03 22:12:02 +00:00
  • 53fca59301 Add namespace support for anonymous requests. Remove unnecessary files from tutorial sample. Ben Alex 2007-12-03 08:07:10 +00:00
  • d086815d75 Add namespace support for anonymous requests. Also minor improvements to .rnc file as Trang didn't appear to be properly translating multi-line comments to the XSD (all multi-line comments were made single lines). Ben Alex 2007-12-03 07:46:52 +00:00
  • 5c9009a391 Use new SpringSecurityFilter so compatible with enhanced FilterChainProxy class. Ben Alex 2007-12-03 07:44:32 +00:00