c2a13b0aa8
[maven-release-plugin] rollback the release of release_1_0_6
Luke Taylor
2007-12-24 16:32:46 +00:00
ad45967cef
[maven-release-plugin] prepare release release_1_0_6
Luke Taylor
2007-12-24 16:26:44 +00:00
bdd78ced7f
Corrected scm element
Luke Taylor
2007-12-24 16:15:11 +00:00
9174fb7746
Removed scm element from core and core-tiger
Luke Taylor
2007-12-24 16:10:34 +00:00
b5ac6e42e3
Reinstated version as 1.0.6-SNAPSHOT after mvn release plugin failure
Luke Taylor
2007-12-24 16:07:24 +00:00
e3247231d7
[maven-release-plugin] prepare release release_1_0_6
Luke Taylor
2007-12-24 16:00:00 +00:00
ab022a5ed3
testing svn commit
Luke Taylor
2007-12-24 15:56:53 +00:00
18d8084744
Fix jetty plugin version at 6.1.6.
Luke Taylor
2007-12-24 14:51:50 +00:00
1216673deb
Fix jetty plugin version at 6.1.6.
Luke Taylor
2007-12-24 14:48:45 +00:00
7ee049c824
Refactored SwitchUserProcessingFilter to extend SpringSecurityFilter.
Luke Taylor
2007-12-23 16:41:30 +00:00
5f1eea42fc
Moved configuration of security interceptors with access and authentication manangers from post processing stage to bean creation stage.
Luke Taylor
2007-12-23 16:40:29 +00:00
46c99d1991
Converted tutorial context file to match namespace changes.
Luke Taylor
2007-12-23 16:36:44 +00:00
5da5bfb7bb
Added "mvn compile" with JDK 1.4 as extra check in build process.
Luke Taylor
2007-12-23 15:07:13 +00:00
27de29f469
Corrected cut and paste error when parsing jdbc-user-service within AuthenticationProvider BDP.
Luke Taylor
2007-12-23 01:26:46 +00:00
ea8914f9ba
Moved Http post processor bean name to BeanIds class.
Luke Taylor
2007-12-23 01:06:22 +00:00
9d671fbdbf
Deleted original Ldap BD parser.
Luke Taylor
2007-12-23 01:05:35 +00:00
14e68618a5
Make constants class abstract.
Luke Taylor
2007-12-23 01:02:48 +00:00
46285a0ec0
SwitchUserProcessingFilter should come after FilterSecurityInterceptor (See SEC-376).
Luke Taylor
2007-12-23 01:02:12 +00:00
a38ed3cfde
Added check for multiple RememberMeServices beans.
Luke Taylor
2007-12-23 00:18:14 +00:00
debfbe47cf
Improvements to LDAP namespace configuration - splitting "ldap" element into ldap-server and ldap-authentication-provider. Also some minor changes to authentication-provider.
Luke Taylor
2007-12-23 00:17:37 +00:00
d0490e6322
Upgraded maven surefire and cobertura plugins.
Luke Taylor
2007-12-21 15:54:38 +00:00
cf80292de3
Changes to namespace reinstating authentication-provider element in preference to "repository" to wrap convey that a user-service will be used as to authenticate against. Also introduced separate password-encoder element for use within authentication-provider.
Luke Taylor
2007-12-21 15:50:56 +00:00
70286f1197
Fixed problem caused by maven-2.0.8 change in test classpath. ldif file wasn't being loaded for tests. Default path should be "classpath*:" not "classpath:". (See discussing in Spring's PathMatchingResourcePatternResolver).
Luke Taylor
2007-12-20 20:53:26 +00:00
6e74d925fb
Boosted logging to try to resolve issues on bamboo server.
Luke Taylor
2007-12-20 19:45:43 +00:00
78e376312a
Added logging of working directory location.
Luke Taylor
2007-12-20 18:29:05 +00:00
85b10f79c2
Made servlet-api integration into an attribute of http, rather than a child element since it has no configuration.
Luke Taylor
2007-12-20 17:51:27 +00:00
1c9bd8bf5f
Updates to release description.
Luke Taylor
2007-12-20 17:47:05 +00:00
e65cb9b472
Made group names singular and added "teller" role.
Luke Taylor
2007-12-14 20:41:33 +00:00
31c09896ea
Fixed problem with relative name being used in (member={0}) search in DefaultAuthoritiesPopulator.
Luke Taylor
2007-12-14 20:41:00 +00:00
09f68400ec
Add <intercept-methods> to example, but it is disabled in favour of @Secured annotation. Still, we include it so people can have a play around and switch between the two syntaxes easily in demos etc.
Ben Alex
2007-12-14 19:56:31 +00:00
55e4568003
Throw an exception instead of sending back a HTTP error code. This is necessary so any demonstration of upgrading from Servlet Spec authorization to Spring Security authorization, as the latter's ExceptionTranslationFilter expects specific exceptions to be thrown if you wish to commence the authentication process.
Ben Alex
2007-12-14 19:44:50 +00:00
2e4773525b
Updated tutorial to allow authentication against ldap provider using <ldap /> namespace element.
Luke Taylor
2007-12-14 19:18:18 +00:00
d90ff50686
Use Java 5 to illustrate annotation support.
Ben Alex
2007-12-14 16:54:10 +00:00
1a171ea316
SEC-595: Introduced loadUserAuthorities method. This can be overridden to allow loading of authorities with the authenticated user's credentials (by setting the security context). The Ldap ContextSource used in the authorities populator would also be configured with a SpringSecurityAuthentcationSource, to make use of the information in the security context.
Luke Taylor
2007-12-14 14:13:39 +00:00
f4c3e701d5
Enhance sample to show method authorization.
Ben Alex
2007-12-14 02:27:48 +00:00
77d286c36f
Enhance tutorial to also demonstrate Spring Security method authorization, and add a services layer accordingly.
Ben Alex
2007-12-14 02:26:27 +00:00
fa510b3187
Modify attribute names to use "ref" instead of "id", plus use a hyphen as an attribute value separator rather than a colon. This was changed for compatibility with other components in the Spring Portfolio. tests pass.
Ben Alex
2007-12-13 20:19:56 +00:00
0f12d31d90
Corrected code for choosing entry point in namespace configuration.
Luke Taylor
2007-12-12 19:44:54 +00:00
7ff533735f
Changes (made by Ben Hale) to support publishing of snapshots and releases to Spring S3 repository.
Ben Alex
2007-12-12 19:06:12 +00:00
6f7590eb05
Updates to sandbox to allow it to compile against latest core changes.
Luke Taylor
2007-12-12 16:15:04 +00:00
1cae1719bc
Fix bean referencing error.
Ben Alex
2007-12-11 19:18:44 +00:00
2655955a40
Add MethodSecurityInterceptor, to more accurately reflect the capabilities offered by auto-config="true".
Ben Alex
2007-12-11 19:14:34 +00:00
9728f48adf
Convert to using AopNamespaceUtils, to avoid potentially creating duplicate DefaultAdvisorAutoProxyCreator bean instances.
Ben Alex
2007-12-11 18:46:20 +00:00
82cfa722be
Upgrade Spring-LDAP to 1.2.1 version.
Luke Taylor
2007-12-11 18:08:44 +00:00
1bbe6ca456
Proper comparison with auto-configure="true".
Ben Alex
2007-12-11 16:44:24 +00:00
ca996de2dc
Added tests for SpringSecurityAuthenticationSource.
Luke Taylor
2007-12-10 23:37:08 +00:00
894c90dadd
Moved AbstractAuthenticationManagerTests into ProviderManager as tested methods have already been moved there (maven wasn't running Abstract* tests but they were actually failing).
Luke Taylor
2007-12-10 23:36:27 +00:00
32038d8b92
Tidying.
Luke Taylor
2007-12-10 19:14:17 +00:00
47dec4e597
Make getters in AbstractRememberMeServices protected rather than public
Luke Taylor
2007-12-10 16:00:49 +00:00
ee31305fd5
Deprecated InitialDirContextFactory
Luke Taylor
2007-12-10 15:29:26 +00:00
5382627d4a
Added property to LdapAuthenticationProvider to allow the credentials to be set either using the submitted password (the default) or the credentials from the loaded UserDetails object (which may be null if the attribute isn't readable).
Luke Taylor
2007-12-09 23:46:28 +00:00
78529f6d28
SEC-620: AuthenticationSource implementation.
Luke Taylor
2007-12-09 23:44:15 +00:00
5e0cb21c8d
SEC-619: Added test class for LdapUserDetailsService. The LdapAuthoritiesPopulator interface and also implementations have been moved to the org.springframework.security.ldap package since they are now used by both the ldap provider and the user service.
Luke Taylor
2007-12-09 18:40:28 +00:00
4770c29094
Use hyphens in attribute names, and not Camel Case. This is to maintain consistency with the rest of Spring Portfolio. Camel Case was preserved for attribute values, consistent with Spring Portfolio usage such as autowiring modes (byName, byType etc).
Ben Alex
2007-12-09 03:42:20 +00:00
6ad176ce1a
Tidying.
Luke Taylor
2007-12-07 17:00:40 +00:00
4984024314
SEC-618: Moved copyDetails method down to ProviderManager so that it can be called prior to checking if authentication is allowed by ConcurrentSessionController.
Luke Taylor
2007-12-07 16:26:50 +00:00
8e6e373a3b
Removed unused import.
Luke Taylor
2007-12-07 16:20:31 +00:00
2b0ee23396
SEC-618: Move copyDetails method into ProviderManager and call it before checking with ConcurrentSessionController.
Luke Taylor
2007-12-07 16:17:59 +00:00
89cde2507d
SEC-594: Set password on UserDetails object returned by BindAuthenticator.
Luke Taylor
2007-12-07 16:04:43 +00:00
b12a4939df
SEC-619: LdapUserDetailsService implementation.
Luke Taylor
2007-12-07 13:16:44 +00:00
a569ff01e2
Tidying.
Luke Taylor
2007-12-07 12:32:54 +00:00
382dc50f3c
SEC-299: Change ConcurrentSessionFilter to delegate to an array of LogoutHandlers rather than invalidating an expired session directly.
Luke Taylor
2007-12-06 17:39:04 +00:00
cb980f12d5
Tidying.
Luke Taylor
2007-12-06 17:26:04 +00:00
628227f5e7
Corrected out of date comment (constructor doesn't create a session). Removed unnecessary default constructor.
Luke Taylor
2007-12-06 16:53:35 +00:00
4b8455c831
Tidying comments.
Luke Taylor
2007-12-06 16:40:16 +00:00
4c6e41af7d
Tidying comments.
Luke Taylor
2007-12-06 16:33:59 +00:00
c66a3ba323
@deprecate FilterToBeanProxy in favour of the simpler and Spring Core provided DelegatingFilterProxy.
Ben Alex
2007-12-06 09:43:43 +00:00
ab23fe56ad
Added log msg for loading of ldif files.
Luke Taylor
2007-12-06 00:14:25 +00:00
a1abcc39d2
SEC-513: Minor work on LDAP UserDetailsManager implementation.
Luke Taylor
2007-12-06 00:13:42 +00:00
e3432c2407
Some changes suggested by Spring LDAP guys to improve template usage.
Luke Taylor
2007-12-06 00:13:00 +00:00
4d133be0d0
Tidying.
Luke Taylor
2007-12-06 00:12:24 +00:00
3ddcc203bf
LdapUserDetailsMapper now throws UnsupportedOperationException for mapUserToContext method as only subclasses of this which implement actual LDAP object classes should be used for writing to a directory.
Luke Taylor
2007-12-06 00:12:06 +00:00
22052115b6
SEC-617: Make LDAPAuthenticationProvider a standalone class.
Luke Taylor
2007-12-05 14:39:46 +00:00
88ab9671c6
Correct attribute name.
Ben Alex
2007-12-04 14:24:53 +00:00
9b6c798a52
SEC-496: <annotation-driven> element.
Ben Alex
2007-12-04 14:14:17 +00:00
949205b369
Correction of equals(Object) and hashCode() methods.
Ben Alex
2007-12-04 12:44:40 +00:00
85085abf9e
Add namespace support for Servlet API integration.
Ben Alex
2007-12-04 12:23:41 +00:00
a205f95c19
No need for an access denied page.
Ben Alex
2007-12-04 11:24:54 +00:00
8c3cc5c67b
Add hash code support.
Ben Alex
2007-12-04 11:21:39 +00:00
8e7c540b16
General refactorings and improvements to namespace support, including autoDetect="true" attribute for <http> element.
Ben Alex
2007-12-04 10:35:08 +00:00
2441ab6d9a
Move "realm" attribute to be on <http> element rather than <http-basic>. This faciltiates reuse with other mechanisms (like Digest) whilst also moving towards the <http-auto-configure> element (which benefits from having shared configuration in <http> as opposed to mechanism-specific elements).
Ben Alex
2007-12-04 08:02:40 +00:00
d9ec944579
Refactor strings to static fields. To facilitate unit testing, package protected visibility was adopted for all element names, attribute names, and attribute default values. A public access modifier was used for all bean IDs assigned to bean definitions created by the BeanDefinitionParsers.
Ben Alex
2007-12-04 07:12:08 +00:00
4e55bd0117
Make extend Spring Security's exception, for consistency with all other Spring Security exceptions.
Ben Alex
2007-12-04 06:58:43 +00:00
9b4bb0ffd8
<repository> element and JdbcUserDetailsManager support.
Ben Alex
2007-12-04 05:58:54 +00:00
5f98ee6817
<repository> element and JdbcUserDetailsManager support.
Ben Alex
2007-12-04 05:54:58 +00:00
0b0b174eda
Support <repository> and JbcUserDetailsManager.
Ben Alex
2007-12-04 05:27:17 +00:00
8cf46ad0f8
Remove, as not used.
Ben Alex
2007-12-04 05:12:39 +00:00
8c9138b443
Typos.
Ben Alex
2007-12-04 02:11:16 +00:00
021f03487e
Enhancements to correctly handle authentication failures.
Ben Alex
2007-12-04 01:50:45 +00:00
2a83843e7d
Correct username key.
Ben Alex
2007-12-04 01:46:26 +00:00
75391e89de
Tidied up Id tag.
Luke Taylor
2007-12-04 00:01:09 +00:00
794795712d
Parameter renamed.
Luke Taylor
2007-12-04 00:00:50 +00:00
97030e8942
Changed LDAP namespace parsing to make sure LDAP provider is registered with ProviderManager.
Luke Taylor
2007-12-03 23:58:38 +00:00
ac0e308354
Updated spring and acegi version numbers in petclinic tutorial file.
Luke Taylor
2007-12-03 23:15:29 +00:00
89d04b54bd
Updated version numbers in petclinic tutorial file.
Luke Taylor
2007-12-03 23:14:10 +00:00
248d97c9d6
SEC-513: Added support for cache flushing after updating or deleting data in JdbcUserDetailsManager.
Luke Taylor
2007-12-03 22:12:02 +00:00
53fca59301
Add namespace support for anonymous requests. Remove unnecessary files from tutorial sample.
Ben Alex
2007-12-03 08:07:10 +00:00
d086815d75
Add namespace support for anonymous requests. Also minor improvements to .rnc file as Trang didn't appear to be properly translating multi-line comments to the XSD (all multi-line comments were made single lines).
Ben Alex
2007-12-03 07:46:52 +00:00
5c9009a391
Use new SpringSecurityFilter so compatible with enhanced FilterChainProxy class.
Ben Alex
2007-12-03 07:44:32 +00:00